STIGQter STIGQter: STIG Summary:

Rancher Government Solutions RKE2 Security Technical Implementation Guide

Version: 2

Release: 7 Benchmark Date: 01 Jul 2026

CheckedNameTitle
☐SV-254553r1188297_ruleRancher RKE2 must protect authenticity of communications sessions with the use of FIPS-validated 140-2 or 140-3 security requirements for cryptographic modules.
☐SV-254554r1043176_ruleRKE2 must use a centralized user management solution to support account management functions.
☐SV-254555r1188300_ruleRancher RKE2 components must be configured in accordance with the security configuration settings based on DOD security configuration or implementation guidance, including SRGs, STIGs, NSA configuration guides, CTOs, and DTMs.
☐SV-254556r1137638_ruleThe Kubernetes Controller Manager must have secure binding.
☐SV-254557r1137638_ruleThe Kubernetes Kubelet must have anonymous authentication disabled.
☐SV-254559r1188303_ruleThe Kubernetes Kubelet must have the read-only port flag disabled.
☐SV-254561r1137639_ruleThe Kubernetes kubelet must enable explicit authorization.
☐SV-254562r1137640_ruleThe Kubernetes API server must have anonymous authentication disabled.
☐SV-254563r960906_ruleAll audit records must identify any containers associated with the event within Rancher RKE2.
☐SV-254564r1156618_ruleConfiguration and authentication files for Rancher RKE2 must be protected.
☐SV-254565r1208189_ruleRancher RKE2 must be configured with only essential configurations.
☐SV-254566r1173952_ruleRancher RKE2 runtime must enforce ports, protocols, and services that adhere to the PPSM CAL.
☐SV-254567r1016559_ruleRancher RKE2 must store only cryptographic representations of passwords.
☐SV-254568r1188305_ruleRancher RKE2 must terminate all network connections associated with a communications session at the end of the session, or as follows: for in-band management sessions (privileged sessions), the session must be terminated after five minutes of inactivity.
☐SV-254569r1188307_ruleRancher RKE2 runtime must isolate security functions from nonsecurity functions.
☐SV-254570r1137645_ruleRancher RKE2 runtime must maintain separate execution domains for each container by assigning each container a separate address space to prevent unauthorized and unintended information transfer via shared system resources.
☐SV-254571r1156616_ruleRancher RKE2 must prevent nonprivileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.
☐SV-254572r1208192_ruleRancher RKE2 must prohibit the installation of patches, updates, and instantiation of container images without explicit privileged status.
☐SV-254574r961677_ruleRancher RKE2 must remove old components after updated versions have been installed.
☐SV-254575r1137649_ruleRancher RKE2 registry must contain the latest images with most recent updates and execute within Rancher RKE2 runtime as authorized by IAVM, CTOs, DTMs, and STIGs.
☐SV-268321r1017019_ruleRancher RKE2 must be built from verified packages.