1.2.7 Ensure that the --authorization-mode argument includes Node

Information

Restrict kubelet nodes to reading only objects associated with them.

The Node authorization mode only allows kubelets to read Secret ConfigMap PersistentVolume and PersistentVolumeClaim objects associated with their nodes.

Solution

Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml on the Control Plane node and set the --authorization-mode parameter to a value that includes Node

--authorization-mode=Node,RBAC

Impact:

None

See Also

https://workbench.cisecurity.org/benchmarks/17568

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|9.2

Plugin: Unix

Control ID: e01b5ef827a6f6e19453357f26e1b324dae2b929fc2864431b020a628a0d8af8