SV-254563r960906_rule
V-254563
SRG-APP-000100-CTR-000200
CNTR-R2-000320
CAT II
10
Edit the RKE2 Configuration File /etc/rancher/rke2/config.yaml on the RKE2 Control Plane and set the following "kube-apiserver-arg" argument:
- audit-log-maxage=30
Once the configuration file is updated, restart the RKE2 Server. Run the command:
systemctl restart rke2-server
Ensure audit-log-maxage is set correctly.
Run the below command on the RKE2 Control Plane:
/bin/ps -ef | grep kube-apiserver | grep -v grep
If --audit-log-maxage argument is not set to at least 30 or is not configured, this is a finding.
(By default, RKE2 sets the --audit-log-maxage argument parameter to 30.)
V-254563
False
CNTR-R2-000320
Ensure audit-log-maxage is set correctly.
Run the below command on the RKE2 Control Plane:
/bin/ps -ef | grep kube-apiserver | grep -v grep
If --audit-log-maxage argument is not set to at least 30 or is not configured, this is a finding.
(By default, RKE2 sets the --audit-log-maxage argument parameter to 30.)
M
5486