3.1.8 Ensure that the admission control policy is not set to AlwaysAdmit

Information

Do not allow all requests.

Rationale:

Setting admission control policy to 'AlwaysAdmit' allows all requests and do not filter any requests.

Solution

Edit the deployment specs and set '--admission-control' argument to a value that does not include 'AlwaysAdmit'.

kubectl edit deployments federation-apiserver-deployment --namespace=federation-system

Impact:

Only requests explicitly allowed by the admissions control policy would be served.

See Also

https://workbench.cisecurity.org/files/1788

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CSCv6|14

Plugin: Unix

Control ID: e24c5901efbd0da89a51a039f64e8309f23bd189b160801d29986aabd7741094