2.1.11 Ensure that the --event-qps argument is set to 0

Information

Do not limit event creation.

Rationale:

It is important to capture all events and not restrict event creation. Events are an important source of security information and analytics that ensure that your environment is consistently monitored using the event data.

Solution

Edit the `/etc/kubernetes/kubelet` file on each node and set the `KUBELET_ARGS` parameter to `'--event-qps=0'`: `KUBELET_ARGS='--event-qps=0'`

Based on your system, restart the `kubelet` service. For example: `systemctl restart kubelet.service`

Impact:

You might need to scale up your event storage and processing capabilitles.

See Also

https://workbench.cisecurity.org/files/1738

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CSCv6|6

Plugin: Unix

Control ID: 9cd7e918b3e471f5f60b6bab9a3a4c19499a99a87249405ebd5a3370855db1a4