| name | cis-gke-v190-3.1.2 |
| description | Ensure that the proxy kubeconfig file ownership is set to root:root (Automated) |
| category | cis-gke |
| version | 1.9.0 |
| author | cyberstrike-official |
| tags | ["cis","gke","kubernetes","gcp","worker-nodes","configuration-files","permissions","ownership","kubeconfig","kubelet"] |
| cis_id | 3.1.2 |
| cis_benchmark | CIS Google Kubernetes Engine (GKE) Benchmark v1.9.0 |
| tech_stack | ["kubernetes","gcp","gke"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
3.1.2 Ensure that the proxy kubeconfig file ownership is set to root:root (Automated)
Profile Applicability
Description
If kube-proxy is running, ensure that the file ownership of its kubeconfig file is set to root:root.
Rationale
The kubeconfig file for kube-proxy controls various parameters for the kube-proxy service in the worker node. You should set its file ownership to maintain the integrity of the file. The file should be owned by root:root.
Impact
Overly permissive file access increases the security risk to the platform.
Audit
Using Google Cloud Console
- Go to Kubernetes Engine by visiting https://console.cloud.google.com/kubernetes/list
- Click on the desired cluster to open the Details page, then click on the desired Node pool to open the Node pool Details page
- Note the name of the desired node
- Go to VM Instances by visiting https://console.cloud.google.com/compute/instances
- Find the desired node and click on 'SSH' to open an SSH connection to the node.
Using Command Line
Method 1
SSH to the worker nodes.
To check to see if the Kubelet Service is running:
sudo systemctl status kubelet
The output should return Active: active (running) since...
Run the following command on each node to find the appropriate kubeconfig file:
ps -ef | grep kubelet
The output of the above command should return something similar to --kubeconfig /var/lib/kubelet/kubeconfig which is the location of the kubeconfig file.
Run this command to obtain the kubeconfig file ownership:
stat -c %U:%G /var/lib/kubelet/kubeconfig
The output of the above command gives you the kubeconfig file's ownership. Verify that the ownership is set to root:root.
Method 2
Create and Run a Privileged Pod.
You will need to run a pod that is privileged enough to access the host's file system. This can be achieved by deploying a pod that uses the hostPath volume to mount the node's file system into the pod.