Skip to content

III - Administrative Public

Rules and Groups employed by this XCCDF Profile

  • The Kubernetes manifests must be owned by root.

    The manifest files contain the runtime configuration of the API server, proxy, scheduler, controller, and etcd. If an attacker can gain access to these files, changes can be made to open vulnerabil...
    Rule Medium Severity
  • SRG-APP-000133-CTR-000300

    Group
  • The Kubernetes KubeletConfiguration file must be owned by root.

    The kubelet configuration file contains the runtime configuration of the kubelet service. If an attacker can gain access to this file, changes can be made to open vulnerabilities and bypass user au...
    Rule Medium Severity
  • SRG-APP-000133-CTR-000305

    Group
  • The Kubernetes KubeletConfiguration files must have file permissions set to 644 or more restrictive.

    The kubelet configuration file contains the runtime configuration of the kubelet service. If an attacker can gain access to this file, changes can be made to open vulnerabilities and bypass user au...
    Rule Medium Severity

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules