CNTR-K8-000910 - Kubernetes Controller Manager must disable profiling.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version

Information

Kubernetes profiling provides the ability to analyze and troubleshoot Controller Manager events over a web interface on a host port. Enabling this service can expose details about the Kubernetes architecture. This service must not be enabled unless deemed necessary.

Solution

Edit the Kubernetes Controller Manager manifest file in the /etc/kubernetes/manifests directory on the Kubernetes Master Node. Set the argument '--profiling value' to 'false'.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Kubernetes_V1R6_STIG.zip

Item Details

References: CAT|II, CCI|CCI-000381, Rule-ID|SV-242409r712583_rule, STIG-ID|CNTR-K8-000910, Vuln-ID|V-242409

Plugin: Unix

Control ID: d802f3d42d129f3287c0d26e4f4343c2ba824b858f53d40de41747d2110197f7