| name | cis-k8s-v1110-1.2.7 |
| description | Ensure that the --authorization-mode argument includes Node (Automated) |
| category | cis-k8s |
| version | 1.11.0 |
| author | cyberstrike-official |
| tags | ["cis","kubernetes","control-plane","api-server","authorization-mode","node-authorization","authorization"] |
| cis_id | 1.2.7 |
| cis_benchmark | CIS Kubernetes Benchmark v1.11.0 |
| tech_stack | ["kubernetes"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
1.2.7 Ensure that the --authorization-mode argument includes Node (Automated)
Profile Applicability
Description
Restrict kubelet nodes to reading only objects associated with them.
Rationale
The Node authorization mode only allows kubelets to read Secret, ConfigMap, PersistentVolume, and PersistentVolumeClaim objects associated with their nodes.
Impact
None
Audit
Run the following command on the Control Plane node:
ps -ef | grep kube-apiserver
Verify that the --authorization-mode argument exists and is set to a value to include Node.
Remediation
Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml on the Control Plane node and set the --authorization-mode parameter to a value that includes Node.
--authorization-mode=Node,RBAC
Default Value
By default, Node authorization is not enabled.
References
- https://kubernetes.io/docs/admin/kube-apiserver/
- https://kubernetes.io/docs/admin/authorization/node/
- https://github.com/kubernetes/kubernetes/pull/46076
- https://acotten.com/post/kube17-security
CIS Controls
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|
| v8 | 3.3 Configure Data Access Control Lists | * | * | * |
| v7 | 9.2 Ensure Only Approved Ports, Protocols and Services Are Running | | * | * |