STIGQter STIGQter: STIG Summary: Rancher Government Solutions Multi-Cluster Manager Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 05 Jan 2026:

Rancher MCM must generate audit records for all DoD-defined auditable events within all components in the platform.

DISA Rule

SV-252844r960777_rule

Vulnerability Number

V-252844

Group Title

SRG-APP-000026-CTR-000070

Rule Version

CNTR-RM-000060

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure audit logging is enabled:

Navigate to Triple Bar Symbol(Global) >> <local cluster>
-From the drop down next to the cluster name, select 'cattle-system'.
-Click "deployments" under Workload menu item.
-Select "rancher" in the Deployments section.
-Click the three dot config menu on the right.
-Choose "Edit Config".
-Scroll down to the "Environment Variables" section.
-Change the AUDIT_LEVEL value to "2" or "3" and then click "Save".

If the variable does not exist:
-Click "Add Variable".
-Keep Default key/Value Pair as "Type"
-Add "AUDIT_LEVEL" as Variable Name.
-Input "2,3" for a value.
-Click "Save".

Check Contents

Ensure audit logging is enabled:

Navigate to Triple Bar Symbol(Global) >> <local cluster>
-From the drop down next to the cluster name, select "cattle-system".
-Click "deployments" under Workload menu item.
-Select "rancher" in the Deployments section.
-Click the three dot config menu on the right.
-Choose "Edit Config".
-Scroll down to the "Environment Variables" section.

If the 'AUDIT_LEVEL' environment variable does not exist or < Level 2, this is a finding.

Vulnerability Number

V-252844

Documentable

False

Rule Version

CNTR-RM-000060

Severity Override Guidance

Ensure audit logging is enabled:

Navigate to Triple Bar Symbol(Global) >> <local cluster>
-From the drop down next to the cluster name, select "cattle-system".
-Click "deployments" under Workload menu item.
-Select "rancher" in the Deployments section.
-Click the three dot config menu on the right.
-Choose "Edit Config".
-Scroll down to the "Environment Variables" section.

If the 'AUDIT_LEVEL' environment variable does not exist or < Level 2, this is a finding.

Check Content Reference

M

Target Key

5467