1.2.7 Ensure that the --authorization-mode argument is not set to AlwaysAllow

Information

Do not always authorize all requests.

Rationale:

The API Server, can be configured to allow all requests. This mode should not be used on any production cluster.

Impact:

Only authorized requests will be served.

Solution

None. RBAC is always on and the OpenShift API server does not use the values assigned to the flag authorization-mode.

Default Value:

OpenShift uses RBAC by default.

See Also

https://workbench.cisecurity.org/benchmarks/14166

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|9.2

Plugin: OpenShift

Control ID: 2591b3e8381dfd522448a41c7a3839537802605d3156811f7da8bba8ef3d4f4c