STIGQter STIGQter: STIG Summary:

Rancher Government Solutions RKE2 Security Technical Implementation Guide

Version: 2

Release: 7 Benchmark Date: 01 Jul 2026

CheckedNameTitle
SV-254553r1188297_ruleRancher RKE2 must protect authenticity of communications sessions with the use of FIPS-validated 140-2 or 140-3 security requirements for cryptographic modules.
SV-254554r1043176_ruleRKE2 must use a centralized user management solution to support account management functions.
SV-254555r1188300_ruleRancher RKE2 components must be configured in accordance with the security configuration settings based on DOD security configuration or implementation guidance, including SRGs, STIGs, NSA configuration guides, CTOs, and DTMs.
SV-254556r1137638_ruleThe Kubernetes Controller Manager must have secure binding.
SV-254557r1137638_ruleThe Kubernetes Kubelet must have anonymous authentication disabled.
SV-254559r1188303_ruleThe Kubernetes Kubelet must have the read-only port flag disabled.
SV-254561r1137639_ruleThe Kubernetes kubelet must enable explicit authorization.
SV-254562r1137640_ruleThe Kubernetes API server must have anonymous authentication disabled.
SV-254563r960906_ruleAll audit records must identify any containers associated with the event within Rancher RKE2.
SV-254564r1156618_ruleConfiguration and authentication files for Rancher RKE2 must be protected.
SV-254565r1208189_ruleRancher RKE2 must be configured with only essential configurations.
SV-254566r1173952_ruleRancher RKE2 runtime must enforce ports, protocols, and services that adhere to the PPSM CAL.
SV-254567r1016559_ruleRancher RKE2 must store only cryptographic representations of passwords.
SV-254568r1188305_ruleRancher RKE2 must terminate all network connections associated with a communications session at the end of the session, or as follows: for in-band management sessions (privileged sessions), the session must be terminated after five minutes of inactivity.
SV-254569r1188307_ruleRancher RKE2 runtime must isolate security functions from nonsecurity functions.
SV-254570r1137645_ruleRancher RKE2 runtime must maintain separate execution domains for each container by assigning each container a separate address space to prevent unauthorized and unintended information transfer via shared system resources.
SV-254571r1156616_ruleRancher RKE2 must prevent nonprivileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures.
SV-254572r1208192_ruleRancher RKE2 must prohibit the installation of patches, updates, and instantiation of container images without explicit privileged status.
SV-254574r961677_ruleRancher RKE2 must remove old components after updated versions have been installed.
SV-254575r1137649_ruleRancher RKE2 registry must contain the latest images with most recent updates and execute within Rancher RKE2 runtime as authorized by IAVM, CTOs, DTMs, and STIGs.
SV-268321r1017019_ruleRancher RKE2 must be built from verified packages.