SV-274882r1137640_rule
V-274882
SRG-APP-000033-CTR-000100
CNTR-K8-001162
CAT I
10
Edit the Kubernetes API Server manifest file in the /etc/kubernetes/manifests directory on the Kubernetes Master Node.
Set the value of "--encryption-provider-config" to the path to the encryption config.
The encryption config must specify the Secret's resource and provider. Below is an example:
{
"kind": "EncryptionConfiguration",
"apiVersion": "apiserver.config.k8s.io/v1",
"resources": [
{
"resources": [
"secrets"
],
"providers": [
{
"aescbc": {
"keys": [
{
"name": "aescbckey",
"secret": "xxxxxxxxxxxxxxxxxxx"
}
]
}
},
{
"identity": {}
}
]
}
]
}
Change to the /etc/kubernetes/manifests directory on the Kubernetes Master Node. Run the command:
grep -i encryption-provider-config *
If the setting "encryption-provider-config" is not configured, this is a finding.
If the setting is configured, check the contents of the file specified by its argument.
If the file does not specify the Secret's resource, this is a finding.
If the identity provider is specified as the first provider for the resource, this is also a finding.
V-274882
False
CNTR-K8-001162
Change to the /etc/kubernetes/manifests directory on the Kubernetes Master Node. Run the command:
grep -i encryption-provider-config *
If the setting "encryption-provider-config" is not configured, this is a finding.
If the setting is configured, check the contents of the file specified by its argument.
If the file does not specify the Secret's resource, this is a finding.
If the identity provider is specified as the first provider for the resource, this is also a finding.
M
5376