CNTR-R2-000550 - Rancher RKE2 must be configured with only essential configurations.

Information

It is important to disable any unnecessary components to reduce any potential attack surfaces.

RKE2 allows disabling the following components:
- rke2-canal
- rke2-coredns
- rke2-ingress-nginx
- rke2-kube-proxy
- rke2-metrics-server

If using any of these components presents a security risk, or if any of the components are not required, they can be disabled by using the "disable" flag.

Satisfies: SRG-APP-000141-CTR-000315, SRG-APP-000384-CTR-000915

Solution

Disable unnecessary RKE2 components.

Edit the RKE2 Server configuration file on all RKE2 Server hosts, located at /etc/rancher/rke2/config.yaml, so that it contains a "disable" flag if any default RKE2 components are unnecessary.

Example:
disable:
- rke2-canal
- rke2-ingress-nginx
- rke2-kube-proxy
- rke2-metrics-server
- rke2-coredns

Once the configuration file is updated, restart the RKE2 Server. Run the command:
systemctl restart rke2-server

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_RGS_RKE2_V2R7_STIG.zip