3.1.8 Ensure that the admission control policy is not set to AlwaysAdmit

Information

Do not allow all requests.

Rationale:

Setting admission control policy to `AlwaysAdmit` allows all requests and do not filter any requests.

Solution

Edit the deployment specs and set `--admission-control` argument to a value that does not include `AlwaysAdmit`. `kubectl edit deployments federation-apiserver-deployment --namespace=federation-system`

Impact:

Only requests explicitly allowed by the admissions control policy would be served.

See Also

https://workbench.cisecurity.org/files/1738

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CSCv6|14

Plugin: Unix

Control ID: 918f5101291b2ba543fc0966982f6004c038b4df98045ddcde2f2d1a4fa24d67