cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌ Cis Ocp V170 1 1 3 · cyberstrikeusEnsure that the controller manager pod specification file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V170 1 1 4 · cyberstrikeusEnsure that the controller manager pod specification file ownership is set to root:root (Manual)
- ▌ Cis Ocp V170 1 1 5 · cyberstrikeusEnsure that the scheduler pod specification file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V170 1 1 6 · cyberstrikeusEnsure that the scheduler pod specification file ownership is set to root:root (Manual)
- ▌ Cis Ocp V170 1 1 7 · cyberstrikeusEnsure that the etcd pod specification file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V170 1 1 8 · cyberstrikeusEnsure that the etcd pod specification file ownership is set to root:root (Manual)
- ▌ Cis Ocp V170 1 1 9 · cyberstrikeusEnsure that the Container Network Interface file permissions are set to 600 or more restrictive (Manual)
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Ocp V170 1 2 5 · cyberstrikeusEnsure that the kubelet uses certificates to authenticate (Manual)
- ▌ Cis Ocp V170 1 2 6 · cyberstrikeusVerify that the kubelet certificate authority is set as appropriate (Manual)
- ▌ Cis Ocp V170 1 2 7 · cyberstrikeusEnsure that the --authorization-mode argument is not set to AlwaysAllow (Manual)
- ▌
- ▌ Cis Ocp V170 1 2 9 · cyberstrikeusEnsure that the APIPriorityAndFairness feature gate is enabled (Manual)
- ▌ Cis Ocp V170 1 3 1 · cyberstrikeusEnsure controller manager healthz endpoints protected by RBAC (Manual)
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Ocp V170 1 4 1 · cyberstrikeusEnsure healthz endpoints for scheduler protected by RBAC (Manual)
- ▌
- ▌ Cis Ocp V170 3 1 1 · cyberstrikeusClient certificate authentication should not be used for users (Manual)
- ▌
- ▌
- ▌ Cis Ocp V170 4 1 1 · cyberstrikeusEnsure that the kubelet service file permissions are set to 644 or more restrictive (Automated)
- ▌ Cis Ocp V170 4 1 2 · cyberstrikeusEnsure that the kubelet service file ownership is set to root:root (Automated)
- ▌ Cis Ocp V170 4 1 3 · cyberstrikeusIf proxy kubeconfig file exists ensure permissions are set to 644 or more restrictive (Manual)
- ▌ Cis Ocp V170 4 1 4 · cyberstrikeusIf proxy kubeconfig file exists ensure ownership is set to root:root (Manual)
- ▌ Cis Ocp V170 4 1 5 · cyberstrikeusEnsure that the --kubeconfig kubelet.conf file permissions are set to 644 or more restrictive (Automated)
- ▌ Cis Ocp V170 4 1 6 · cyberstrikeusEnsure that the --kubeconfig kubelet.conf file ownership is set to root:root (Automated)
- ▌ Cis Ocp V170 4 1 7 · cyberstrikeusEnsure that the certificate authorities file permissions are set to 644 or more restrictive (Automated)
- ▌ Cis Ocp V170 4 1 8 · cyberstrikeusEnsure that the client certificate authorities file ownership is set to root:root (Automated)
- ▌ Cis Ocp V170 4 1 9 · cyberstrikeusEnsure that the kubelet --config configuration file has permissions set to 600 or more restrictive (Automated)
- ▌ Cis Ocp V170 4 2 1 · cyberstrikeusActivate Garbage collection in OpenShift Container Platform 4, as appropriate (Manual)
- ▌ Cis Ocp V170 4 2 2 · cyberstrikeusEnsure that the --anonymous-auth argument is set to false (Automated)
- ▌ Cis Ocp V170 4 2 3 · cyberstrikeusEnsure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
- ▌ Cis Ocp V170 4 2 4 · cyberstrikeusEnsure that the --client-ca-file argument is set as appropriate (Automated)
- ▌ Cis Ocp V170 4 2 5 · cyberstrikeusVerify that the read only port is not used or is set to 0 (Automated)
- ▌ Cis Ocp V170 4 2 6 · cyberstrikeusEnsure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)
- ▌ Cis Ocp V170 4 2 7 · cyberstrikeusEnsure that the --make-iptables-util-chains argument is set to true (Manual)
- ▌ Cis Ocp V170 4 2 8 · cyberstrikeusEnsure that the kubeAPIQPS [--event-qps] argument is set to 0 or a level which ensures appropriate event capture (Manual)
- ▌ Cis Ocp V170 4 2 9 · cyberstrikeusEnsure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Ocp V170 5 1 6 · cyberstrikeusEnsure Service Account Tokens only mounted where necessary (Manual)
- ▌
- ▌ Cis Ocp V170 5 2 2 · cyberstrikeusMinimize admission of containers sharing host process ID namespace (Manual)
- ▌ Cis Ocp V170 5 2 3 · cyberstrikeusMinimize admission of containers sharing host IPC namespace (Manual)
- ▌ Cis Ocp V170 5 2 4 · cyberstrikeusMinimize admission of containers sharing host network namespace (Manual)
- ▌ Cis Ocp V170 5 2 5 · cyberstrikeusMinimize admission of containers with allowPrivilegeEscalation (Manual)
- ▌
- ▌ Cis Ocp V170 5 2 7 · cyberstrikeusMinimize admission of containers with NET_RAW capability (Manual)
- ▌ Cis Ocp V170 5 2 8 · cyberstrikeusMinimize admission of containers with added capabilities (Manual)
- ▌ Cis Ocp V170 5 2 9 · cyberstrikeusMinimize admission of containers with capabilities assigned (Manual)
- ▌
- ▌
- ▌ Cis Ocp V170 5 4 1 · cyberstrikeusPrefer using secrets as files over environment variables (Manual)
- ▌
- ▌ Cis Ocp V170 5 5 1 · cyberstrikeusConfigure Image Provenance using image controller config (Manual)
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Ocp V190 1 1 1 · cyberstrikeusEnsure that the API server pod specification file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V190 1 1 2 · cyberstrikeusEnsure that the API server pod specification file ownership is set to root:root (Manual)
- ▌ Cis Ocp V190 1 1 3 · cyberstrikeusEnsure that the controller manager pod specification file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V190 1 1 4 · cyberstrikeusEnsure that the controller manager pod specification file ownership is set to root:root (Manual)
- ▌ Cis Ocp V190 1 1 5 · cyberstrikeusEnsure that the scheduler pod specification file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V190 1 1 6 · cyberstrikeusEnsure that the scheduler pod specification file ownership is set to root:root (Manual)
- ▌ Cis Ocp V190 1 1 7 · cyberstrikeusEnsure that the etcd pod specification file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V190 1 1 8 · cyberstrikeusEnsure that the etcd pod specification file ownership is set to root:root (Manual)
- ▌ Cis Ocp V190 1 1 9 · cyberstrikeusEnsure that the Container Network Interface file permissions are set to 600 or more restrictive (Manual)
- ▌
- ▌
- ▌ Cis Ocp V190 1 2 3 · cyberstrikeusEnsure that the kubelet uses certificates to authenticate (Manual)
- ▌ Cis Ocp V190 1 2 4 · cyberstrikeusVerify that the kubelet certificate authority is set as appropriate (Manual)
- ▌ Cis Ocp V190 1 2 5 · cyberstrikeusEnsure that the --authorization-mode argument is not set to AlwaysAllow (Manual)
- ▌
- ▌ Cis Ocp V190 1 2 7 · cyberstrikeusEnsure that the APIPriorityAndFairness feature gate is enabled (Manual)
- ▌ Cis Ocp V190 1 2 8 · cyberstrikeusEnsure that the admission control plugin AlwaysAdmit is not set (Manual)
- ▌ Cis Ocp V190 1 2 9 · cyberstrikeusEnsure that the admission control plugin AlwaysPullImages is not set (Manual)
- ▌ Cis Ocp V190 1 3 1 · cyberstrikeusEnsure that controller manager healthz endpoints are protected by RBAC (Manual)
- ▌ Cis Ocp V190 1 3 2 · cyberstrikeusEnsure that the --use-service-account-credentials argument is set to true (Manual)
- ▌ Cis Ocp V190 1 3 3 · cyberstrikeusEnsure that the --service-account-private-key-file argument is set as appropriate (Manual)
- ▌ Cis Ocp V190 1 3 4 · cyberstrikeusEnsure that the --root-ca-file argument is set as appropriate (Manual)
- ▌ Cis Ocp V190 1 4 1 · cyberstrikeusEnsure that the healthz endpoints for the scheduler are protected by RBAC (Manual)
- ▌ Cis Ocp V190 1 4 2 · cyberstrikeusVerify that the scheduler API service is protected by RBAC (Manual)
- ▌ Cis Ocp V190 3 1 1 · cyberstrikeusClient certificate authentication should not be used for users (Manual)
- ▌
- ▌ Cis Ocp V190 3 2 2 · cyberstrikeusEnsure that the audit policy covers key security concerns (Manual)
- ▌ Cis Ocp V190 4 1 1 · cyberstrikeusEnsure that the kubelet service file permissions are set to 644 or more restrictive (Automated)
- ▌ Cis Ocp V190 4 1 2 · cyberstrikeusEnsure that the kubelet service file ownership is set to root:root (Automated)
- ▌ Cis Ocp V190 4 1 3 · cyberstrikeusIf proxy kube proxy configuration file exists ensure permissions are set to 644 or more restrictive (Manual)
- ▌ Cis Ocp V190 4 1 4 · cyberstrikeusIf proxy kubeconfig file exists ensure ownership is set to root:root (Manual)
- ▌ Cis Ocp V190 4 1 5 · cyberstrikeusEnsure that the --kubeconfig kubelet.conf file permissions are set to 644 or more restrictive (Automated)