cis-ocp-v190-4.2.12
Ensure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Ensure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)
Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
Ensure that the --client-ca-file argument is set as appropriate (Automated)
Verify that the read only port is not used or is set to 0 (Automated)
Ensure that the --make-iptables-util-chains argument is set to true (Manual)
Ensure that the kubeAPIQPS [--event-qps] argument is set to a level which ensures appropriate event capture (Manual)
Ensure that the cluster-admin role is only used where required (Manual)
Minimize wildcard use in Roles and ClusterRoles (Manual)
Minimize access to create pods (Manual)
Ensure that default service accounts are not actively used (Manual)