3.1.2 Ensure that the proxy kubeconfig file ownership is set to root:root

Information

If kube-proxy is running, ensure that the file ownership of its kubeconfig file is set to root:root.

Rationale:

The kubeconfig file for kube-proxy controls various parameters for the kube-proxy service in the worker node. You should set its file ownership to maintain the integrity of the file. The file should be owned by root:root.

Impact:

Overly permissive file access increases the security risk to the platform.

Solution

Run the below command (based on the file location on your system) on each worker node. For example,

chown root:root <proxy kubeconfig file>

Default Value:

The default ownership of the proxy kubeconfig file is root:root.

See Also

https://workbench.cisecurity.org/benchmarks/13178