CNTR-K8-000420 - Kubernetes dashboard must not be enabled.

Information

While the Kubernetes dashboard is not inherently insecure on its own, it is often coupled with a misconfiguration of Role-Based Access control (RBAC) permissions that can unintentionally over-grant access. It is not commonly protected with 'NetworkPolicies', preventing all pods from being able to reach it. In increasingly rare circumstances, the Kubernetes dashboard is exposed publicly to the internet.

Solution

Delete the Kubernetes dashboard deployment with the following command:

kubectl delete deployment kubernetes-dashboard --namespace=kube-system

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Kubernetes_V1R11_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CAT|II, CCI|CCI-000213, Rule-ID|SV-242395r879530_rule, STIG-ID|CNTR-K8-000420, Vuln-ID|V-242395

Plugin: Unix

Control ID: 03594d1a8e6039580a2e1fcd1a612ae019edcb139bb87b41700bb1739e1de8bf