STIGQter STIGQter: STIG Summary: Rancher Government Solutions RKE2 Security Technical Implementation Guide Version: 2 Release: 7 Benchmark Date: 01 Jul 2026:

Rancher RKE2 must be built from verified packages.

DISA Rule

SV-268321r1017019_rule

Vulnerability Number

V-268321

Group Title

SRG-APP-000131-CTR-000285

Rule Version

CNTR-R2-000460

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Immediate action must be taken to remove non-verifiable images from the cluster and replace them with verifiable images.

Utilize Hauler (https://hauler.dev) to pull and verify RKE2 images from Rancher Government Solutions Carbide Repository.

For more information about pulling Carbide images and their signatures, including RKE2, see:
https://rancherfederal.github.io/carbide-docs/docs/registry-docs/downloading-images

Check Contents

Utilizing Hauler (https://hauler.dev), ensure all RKE2 Kubernetes Container images running in the RKE2 cluster have been obtained and their signatures have been validated and signed by Rancher Government Solutions Private Key.
For reference, the public key is available at:
https://raw.githubusercontent.com/rancherfederal/carbide-releases/main/carbide-key.pub

For more information about verifying the signatures of Carbide images, including RKE2, see:
https://rancherfederal.github.io/carbide-docs/docs/registry-docs/validating-images

If any RKE2 images are identified as not being signed by the Rancher Government Solutions' private key, this is a finding.

Vulnerability Number

V-268321

Documentable

False

Rule Version

CNTR-R2-000460

Severity Override Guidance

Utilizing Hauler (https://hauler.dev), ensure all RKE2 Kubernetes Container images running in the RKE2 cluster have been obtained and their signatures have been validated and signed by Rancher Government Solutions Private Key.
For reference, the public key is available at:
https://raw.githubusercontent.com/rancherfederal/carbide-releases/main/carbide-key.pub

For more information about verifying the signatures of Carbide images, including RKE2, see:
https://rancherfederal.github.io/carbide-docs/docs/registry-docs/validating-images

If any RKE2 images are identified as not being signed by the Rancher Government Solutions' private key, this is a finding.

Check Content Reference

M

Target Key

5486