3.1.8 Ensure that the admission control policy is not set to AlwaysAdmit

Information

Do not allow all requests.

Rationale:

Setting admission control policy to `AlwaysAdmit` allows all requests and do not filter any requests.

Solution

Edit the deployment specs and set `--admission-control` argument to a value that does not include `AlwaysAdmit`. `kubectl edit deployments federation-apiserver-deployment --namespace=federation-system`

Impact:

Only requests explicitly allowed by the admissions control policy would be served.

See Also

https://workbench.cisecurity.org/files/1738

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CSCv6|14

Plugin: Unix

Control ID: c66c07370735ed807cb41e6ecc5ae6fc50829fe8bc38194680636dde82893eb1