1.2.10 Ensure that the admission control plugin AlwaysAdmit is not set

Information

Do not allow all requests.

Setting admission control plugin AlwaysAdmit allows all requests and does not filter any requests.

The AlwaysAdmit admission controller was deprecated in Kubernetes v1.13. Its behavior was equivalent to turning off all admission controllers.

Solution

None.

Impact:

Only requests explicitly allowed by the admissions control plugins would be served.

See Also

https://workbench.cisecurity.org/benchmarks/19464

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: OpenShift

Control ID: f47d24365d4115de83d3a38b67c65606d705f42c31bfbf253dc6e5be10ac97ce