SV-260933r966156_rule
V-260933
SRG-APP-000233-CTR-000585
CNTR-MK-000990
CAT II
10
When using Kubernetes orchestration, edit the Kubernetes Kubelet file in the /etc/sysconfig directory on the Kubernetes Control Plane. Set the argument "--protect-kernel-defaults" to "true".
Reset Kubelet service using the following command:
service kubelet restart
When using Swarm orchestration, review and remove nonsystem containers previously created by these users that allowed capabilities to be added or must be removed using:
docker container rm [container]
Verify kernel protection.
When using Kubernetes orchestration, change to the /etc/sysconfig/ directory on the Kubernetes Control Plane using the command:
grep -i protect-kernel-defaults kubelet
If the setting "protect-kernel-defaults" is set to false or not set in the Kubernetes Kubelet, this is a finding.
When using Swarm orchestration:
Linux: Execute the following command as a trusted user on the host operating system:
docker ps --quiet --all | xargs docker inspect --format '{{ .Name }}: CapAdd={{ .HostConfig.CapAdd }} CapDrop={{ .HostConfig.CapDrop }}'
The command will output all Linux Kernel Capabilities.
If Linux Kernel Capabilities exceed what is defined in the System Security Plan (SSP), this is a finding.
V-260933
False
CNTR-MK-000990
Verify kernel protection.
When using Kubernetes orchestration, change to the /etc/sysconfig/ directory on the Kubernetes Control Plane using the command:
grep -i protect-kernel-defaults kubelet
If the setting "protect-kernel-defaults" is set to false or not set in the Kubernetes Kubelet, this is a finding.
When using Swarm orchestration:
Linux: Execute the following command as a trusted user on the host operating system:
docker ps --quiet --all | xargs docker inspect --format '{{ .Name }}: CapAdd={{ .HostConfig.CapAdd }} CapDrop={{ .HostConfig.CapDrop }}'
The command will output all Linux Kernel Capabilities.
If Linux Kernel Capabilities exceed what is defined in the System Security Plan (SSP), this is a finding.
M
5595