STIGQter STIGQter: STIG Summary:

Mirantis Kubernetes Engine Security Technical Implementation Guide

Version: 2

Release: 1 Benchmark Date: 24 Jul 2024

CheckedNameTitle
SV-260903r1015767_ruleThe Lifetime Minutes and Renewal Threshold Minutes Login Session Controls on MKE must be set.
SV-260904r966069_ruleIn an MSR organization, user permissions and repositories must be configured.
SV-260905r966072_ruleUser-managed resources must be created in dedicated namespaces.
SV-260906r1015768_ruleLeast privilege access and need to know must be required to access MKE runtime and instantiate container images.
SV-260907r966078_ruleOnly required ports must be open on containers in MKE.
SV-260908r966081_ruleFIPS mode must be enabled.
SV-260909r1015769_ruleMKE must be configured to integrate with an Enterprise Identity Provider.
SV-260910r966087_ruleSSH must not run within Linux containers.
SV-260911r1015770_ruleSwarm Secrets or Kubernetes Secrets must be used.
SV-260912r966093_ruleMKE must have Grants created to control authorization to cluster resources.
SV-260913r966096_ruleMKE host network namespace must not be shared.
SV-260914r966099_ruleAudit logging must be enabled on MKE.
SV-260915r966102_ruleMKE must be configured to send audit data to a centralized log server.
SV-260916r966105_ruleMSR's self-signed certificates must be replaced with DOD trusted, signed certificates.
SV-260917r966108_ruleAllowing users and administrators to schedule containers on all nodes must be disabled.
SV-260918r966111_ruleMKE telemetry must be disabled.
SV-260919r966114_ruleMSR telemetry must be disabled.
SV-260920r966117_ruleFor MKE's deployed on an Ubuntu host operating system, the AppArmor profile must be enabled.
SV-260921r966120_ruleIf MKE is deployed on a Red Hat or CentOS system, SELinux security must be enabled.
SV-260922r966123_ruleThe Docker socket must not be mounted inside any containers.
SV-260923r966126_ruleLinux Kernel capabilities must be restricted within containers.
SV-260924r966129_ruleIncoming container traffic must be bound to a specific host interface.
SV-260925r966132_ruleCPU priority must be set appropriately on all containers.
SV-260926r966135_ruleMKE must use a non-AUFS storage driver.
SV-260927r966138_ruleMKE's self-signed certificates must be replaced with DOD trusted, signed certificates.
SV-260928r966141_ruleThe "Create repository on push" option in MSR must be disabled.
SV-260929r966144_ruleContainers must not map to privileged ports.
SV-260930r966147_ruleMKE must not permit users to create pods that share host process namespace.
SV-260931r966150_ruleIPSec network encryption must be configured.
SV-260932r966153_ruleMKE must preserve any information necessary to determine the cause of the disruption or failure.
SV-260933r966156_ruleMKE must enable kernel protection.
SV-260934r966159_ruleAll containers must be restricted from acquiring additional privileges.
SV-260935r966162_ruleHost IPC namespace must not be shared.
SV-260936r966165_ruleAll containers must be restricted to mounting the root filesystem as read only.
SV-260937r966168_ruleThe default seccomp profile must not be disabled.
SV-260938r1015771_ruleDocker CLI commands must be run with an MKE client trust bundle and without unnecessary permissions.
SV-260939r966174_ruleMKE users must not have permissions to create containers or pods that share the host user namespace.
SV-260940r966177_ruleUse of privileged Linux containers must be limited to system containers.
SV-260941r966180_ruleThe network ports on all running containers must be limited to required ports.
SV-260942r1015772_ruleMKE must only run signed images.
SV-260943r966186_ruleVulnerability scanning must be enabled for all repositories in MSR.
SV-260944r966189_ruleOlder Universal Control Plane (MKE) and Docker Trusted Registry (DTR) images must be removed from all cluster nodes upon upgrading.
SV-260945r966192_ruleMKE must contain the latest updates.
SV-260946r966345_ruleMKE must display the Standard Mandatory DOD Notice and Consent Banner before granting access to platform components.