Skip to content

III - Administrative Public

Rules and Groups employed by this XCCDF Profile

  • SRG-APP-000033-CTR-000095

    Group
  • The Kubernetes kubelet must enable explicit authorization.

    Kubelet is the primary agent on each node. The API server communicates with each kubelet to perform tasks such as starting/stopping pods. By default, kubelets allow all authenticated requests, even...
    Rule High Severity
  • SRG-APP-000033-CTR-000095

    Group
  • Kubernetes Worker Nodes must not have sshd service running.

    Worker Nodes are maintained and monitored by the Control Plane. Direct access and manipulation of the nodes should not take place by administrators. Worker nodes should be treated as immutable and ...
    Rule Medium Severity
  • SRG-APP-000033-CTR-000095

    Group

The content of the drawer really is up to you. It could have form fields, definition lists, text lists, labels, charts, progress bars, etc. Spacing recommendation is 24px margins. You can put tabs in here, and can also make the drawer scrollable.

Capacity
Modules