0400-k8s-node-conf-priv-kubernetes Configuration File Permissions Not Set to 644 or More Restrictive¶
Rule ID¶
- 0400-k8s-node-conf-priv
Category¶
- container
Level¶
- warn
Compatible Versions¶
- Linux
Description¶
- If you are using a Kubernetes node on a machine where systemd manages services, verify that the
kubernetes.servicefile permissions are correctly set to644or more restrictive.
Scan Frequency¶
0 */30 * * *
Rationale¶
- The
kubernetes.servicefile contains sensitive parameters that can change the behavior of the Kubernetes daemon. Therefore, no user other than root should have write access to it in order to maintain file integrity.
Risk Items¶
- Container Security
Audit Method¶
- Execute the following command to verify that the file permissions are set to
644or more restrictive:
stat -c %a /etc/systemd/system/kubelet.service.d/10-kubeadm.conf
stat -c %a /etc/kubernetes/kubelet.conf
stat -c %a /var/lib/kubelet/config.yaml
Remediation¶
- Execute the following command to change the permissions of the three configuration files:
#> chmod 644 /etc/systemd/system/kubelet.service.d/10-kubeadm.conf /etc/kubernetes/kubelet.conf /var/lib/kubelet/config.yaml
This sets the file permissions to 644.
Impact¶
- None
Default Value¶
- This file may not exist on the system. In that case, this recommendation does not apply. By default, if the file exists, the file permissions are correctly set to
644.
References¶
CIS Controls¶
- None