STIGQter STIGQter: STIG Summary: Kubernetes Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 13 Apr 2021:

The Kubernetes kubelet configuration file must be owned by root.

DISA Rule

SV-242406r712574_rule

Vulnerability Number

V-242406

Group Title

SRG-APP-000133-CTR-000300

Rule Version

CNTR-K8-000880

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

On the Master and Worker nodes, change to the /etc/sysconfig directory. Run the command:

chown root:root kubelet

To verify the change took place, run the command:

ls -l kubelet

The kubelet file should now be owned by root:root.

Check Contents

On the Master and worker nodes, change to the /etc/sysconfig directory. Run the command:

ls -l kubelet

Each kubelet configuration file must be owned by root:root.

If any manifest file is not owned by root:root, this is a finding.

Vulnerability Number

V-242406

Documentable

False

Rule Version

CNTR-K8-000880

Severity Override Guidance

On the Master and worker nodes, change to the /etc/sysconfig directory. Run the command:

ls -l kubelet

Each kubelet configuration file must be owned by root:root.

If any manifest file is not owned by root:root, this is a finding.

Check Content Reference

M

Target Key

5376

Comments