CNTR-K8-001990 - Kubernetes must prevent non-privileged users from executing privileged functions to include disabling, circumventing, or altering implemented security safeguards/countermeasures or the installation of patches and updates.

Information

Kubernetes uses the API Server to control communication to the other services that makeup Kubernetes. The use of authorizations and not the default of 'AlwaysAllow' enables the Kubernetes functions control to only the groups that need them.

To control access the API server must have one of the following options set for the authorization mode:
--authorization-mode=ABAC Attribute-Based Access Control (ABAC) mode allows a user to configure policies using local files.
--authorization-mode=RBAC Role-based access control (RBAC) mode allows a user to create and store policies using the Kubernetes API.
--authorization-mode=Webhook

WebHook is an HTTP callback mode that allows a user to manage authorization using a remote REST endpoint.
--authorization-mode=Node

Node authorization is a special-purpose authorization mode that specifically authorizes API requests made by kubelets.
--authorization-mode=AlwaysDeny

This flag blocks all requests. Use this flag only for testing.

Satisfies: SRG-APP-000340-CTR-000770, SRG-APP-000033-CTR-000095, SRG-APP-000378-CTR-000880

Solution

Edit the Kubernetes API Server manifest file in the /etc/kubernetes/manifests directory on the Kubernetes Master Node. Set the argument '--authorization-mode' to any valid authorization mode other than AlwaysAllow.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Kubernetes_V1R6_STIG.zip

Item Details

Category: ACCESS CONTROL, CONFIGURATION MANAGEMENT

References: 800-53|AC-3, 800-53|AC-6(10), 800-53|CM-11(2), CAT|I, CCI|CCI-000213, CCI|CCI-001812, CCI|CCI-002235, Rule-ID|SV-242435r712661_rule, STIG-ID|CNTR-K8-001990, Vuln-ID|V-242435

Plugin: Unix

Control ID: 22a3a347445b16f16de48178af9ab84057f71a20fade10717a5ba987b9b155de