Skip to content

0400-k8s-node-conf-priv-kubernetes Configuration File Permissions Not Set to 644 or More Restrictive

Rule ID

  • 0400-k8s-node-conf-priv

Category

  • container

Level

  • warn

Compatible Versions

  • Linux

Description

  • If you are using a Kubernetes node on a machine where systemd manages services, verify that the kubernetes.service file permissions are correctly set to 644 or more restrictive.

Scan Frequency

  • 0 */30 * * *

Rationale

  • The kubernetes.service file contains sensitive parameters that can change the behavior of the Kubernetes daemon. Therefore, no user other than root should have write access to it in order to maintain file integrity.

Risk Items

  • Container Security

Audit Method

  • Execute the following command to verify that the file permissions are set to 644 or more restrictive:
stat -c %a /etc/systemd/system/kubelet.service.d/10-kubeadm.conf
stat -c %a /etc/kubernetes/kubelet.conf
stat -c %a /var/lib/kubelet/config.yaml

Remediation

  • Execute the following command to change the permissions of the three configuration files:
#> chmod 644 /etc/systemd/system/kubelet.service.d/10-kubeadm.conf /etc/kubernetes/kubelet.conf /var/lib/kubelet/config.yaml

This sets the file permissions to 644.

Impact

  • None

Default Value

  • This file may not exist on the system. In that case, this recommendation does not apply. By default, if the file exists, the file permissions are correctly set to 644.

References

CIS Controls

  • None

Feedback

Is this page helpful?