SV-254574r961677_rule
V-254574
SRG-APP-000454-CTR-001110
CNTR-R2-001580
CAT II
10
Remove any old pods that are using older images. On the RKE2 Control Plane, run the command:
kubectl delete pod podname
(Note: "podname" is the name of the pod to delete.)
Run the command:
systemctl restart rke2-server
To view all pods and the images used to create the pods, from the RKE2 Control Plane, run the following command:
kubectl get pods --all-namespaces -o jsonpath="{..image}" | \
tr -s '[[:space:]]' '\n' | \
sort | \
uniq -c
Review the images used for pods running within Kubernetes.
If there are multiple versions of the same image, this is a finding.
V-254574
False
CNTR-R2-001580
To view all pods and the images used to create the pods, from the RKE2 Control Plane, run the following command:
kubectl get pods --all-namespaces -o jsonpath="{..image}" | \
tr -s '[[:space:]]' '\n' | \
sort | \
uniq -c
Review the images used for pods running within Kubernetes.
If there are multiple versions of the same image, this is a finding.
M
5486