cis-k8s-v1110-2.7
Ensure that the --peer-auto-tls argument is not set to true (Automated)
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Ensure that the --peer-auto-tls argument is not set to true (Automated)
Ensure that a unique Certificate Authority is used for etcd (Manual)
Service account token authentication should not be used for users (Manual)
Bootstrap token authentication should not be used for users (Manual)
Ensure that a minimal audit policy is created (Manual)
Ensure that the audit policy covers key security concerns (Manual)
Ensure that the kubelet service file permissions are set to 600 or more restrictive (Automated)
If the kubelet config.yaml configuration file is being used validate file ownership is set to root:root (Automated)
Ensure that the kubelet service file ownership is set to root:root (Automated)
If proxy kubeconfig file exists ensure permissions are set to 600 or more restrictive (Manual)