1.2.9 Ensure that the APIPriorityAndFairness feature gate is enabled

Information

Limit the rate at which the API server accepts requests.

A misbehaving workload could overwhelm and DoS the API Server, making it unavailable. This particularly applies to a multi-tenant cluster, where there might be a small percentage of misbehaving tenants which could have a significant impact on the performance of the cluster overall. Hence, it is recommended to limit the rate of events that the API server will accept.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

No remediation is required.

Impact:

None, as the OpenShift kubelet has been fixed to send fewer requests.

See Also

https://workbench.cisecurity.org/benchmarks/19464

Item Details

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-18, 800-53|SC-23, CSCv7|8.3

Plugin: OpenShift

Control ID: dc818a81f76709e67aec859cf1e1749dcb51baecab893da3506366c7868793bf