1.1.9 Ensure that the admission control policy is not set to AlwaysAdmit

Information

Do not allow all requests.

Rationale:

Setting admission control policy to 'AlwaysAdmit' allows all requests and do not filter any requests.

Solution

Edit the API server pod specification file '/etc/kubernetes/manifests/kube-apiserver.yaml' on the master node and set the '--admission-control' parameter to a value that does not include 'AlwaysAdmit'.

Impact:

Only requests explicitly allowed by the admissions control policy would be served.

See Also

https://workbench.cisecurity.org/files/1788

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CSCv6|14

Plugin: Unix

Control ID: 4a693ee80c8403588dd4325e1f6c6e36c5af365ac7200fb1777611fad6bf391a