STIGQter STIGQter: STIG Summary: Mirantis Kubernetes Engine Security Technical Implementation Guide Version: 2 Release: 1 Benchmark Date: 24 Jul 2024:

If MKE is deployed on a Red Hat or CentOS system, SELinux security must be enabled.

DISA Rule

SV-260921r966120_rule

Vulnerability Number

V-260921

Group Title

SRG-APP-000141-CTR-000315

Rule Version

CNTR-MK-000530

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

If using MKE on operating systems other than Red Hat Enterprise Linux or CentOS host operating systems where SELinux is in use, this check is Not Applicable.

Execute on all nodes in a cluster.

Start MKE with SELinux mode enabled. Run containers using appropriate security options.

Via CLI:
Linux: Set the SELinux state and policy. Create or import a SELinux policy template for MKE. Then, start MKE with SELinux mode enabled by setting the "selinux-enabled" property to "true" in the "/etc/docker/daemon.json" daemon configuration file.

Restart MKE.

Check Contents

If using MKE on operating systems other than Red Hat Enterprise Linux or CentOS host operating systems where SELinux is in use, this check is Not Applicable.

Execute on all nodes in a cluster.

Verify that the appropriate security options are configured for all running containers:

Via CLI:
Linux: Execute the following command as a user on the host operating system:

docker info --format '{{.SecurityOptions}}'

expected output [name=seccomp, profile=default name=selinux name=fips]

If there is no output or name does not equal SELinux, this is a finding.

Vulnerability Number

V-260921

Documentable

False

Rule Version

CNTR-MK-000530

Severity Override Guidance

If using MKE on operating systems other than Red Hat Enterprise Linux or CentOS host operating systems where SELinux is in use, this check is Not Applicable.

Execute on all nodes in a cluster.

Verify that the appropriate security options are configured for all running containers:

Via CLI:
Linux: Execute the following command as a user on the host operating system:

docker info --format '{{.SecurityOptions}}'

expected output [name=seccomp, profile=default name=selinux name=fips]

If there is no output or name does not equal SELinux, this is a finding.

Check Content Reference

M

Target Key

5595