CIS RedHat OpenShift Container Platform 4 v1.3.0 L2

Warning! Audit Deprecated

This audit file has been deprecated and will be removed in a future update.

View Next Version

Audit Details

Name: CIS RedHat OpenShift Container Platform 4 v1.3.0 L2

Updated: 11/28/2023

Authority: CIS

Plugin: OpenShift

Revision: 1.1

Estimated Item Count: 33

Audit Items

DescriptionCategories
1.3.6 Ensure that the RotateKubeletServerCertificate argument is set to true
2.7 Ensure that a unique Certificate Authority is used for etcd
2.8 Encrypt etc
3.1.1 Client certificate authentication should not be used for users - Authentications
3.1.1 Client certificate authentication should not be used for users - ClusterRoleBindings
3.1.1 Client certificate authentication should not be used for users - Identities
3.1.1 Client certificate authentication should not be used for users - Secrets
3.2.2 Ensure that the audit policy covers key security concerns - openshift-apiserver
3.2.2 Ensure that the audit policy covers key security concerns - openshift-kube-apiserver
4.2.9 Ensure that the kubeAPIQPS [--event-qps] argument is set to 0 or a level which ensures appropriate event capture
5.2.6 Minimize the admission of root containers
5.2.9 Minimize the admission of containers with capabilities assigned
5.3.2 Ensure that all Namespaces have Network Policies defined - Namespaces
5.3.2 Ensure that all Namespaces have Network Policies defined - NetworkPolicies
5.4.2 Consider external secret storage
5.5.1 Configure Image Provenance using image controller configuration parameters
5.7.2 Ensure that the seccomp profile is set to docker/default in your pod definitions
5.7.3 Apply Security Context to Your Pods and Containers
5.7.4 The default namespace should not be used - BuildConfigs
5.7.4 The default namespace should not be used - Builds
5.7.4 The default namespace should not be used - CronJobs
5.7.4 The default namespace should not be used - DaemonSets
5.7.4 The default namespace should not be used - DeploymentConfigs
5.7.4 The default namespace should not be used - Deployments
5.7.4 The default namespace should not be used - HorizontalPodAutoScalers
5.7.4 The default namespace should not be used - ImageStreams
5.7.4 The default namespace should not be used - Jobs
5.7.4 The default namespace should not be used - Pods
5.7.4 The default namespace should not be used - ReplicaSets
5.7.4 The default namespace should not be used - ReplicationControllers
5.7.4 The default namespace should not be used - Routes
5.7.4 The default namespace should not be used - Services
5.7.4 The default namespace should not be used - StatefulSets