5.3.1 Ensure that the CNI in use supports Network Policies

Information

There are a variety of CNI plugins available for Kubernetes. If the CNI in use does not support Network Policies it may not be possible to effectively restrict traffic in the cluster.

Rationale:

Kubernetes network policies are enforced by the CNI plugin in use. As such it is important to ensure that the CNI plugin supports both Ingress and Egress network policies.

Impact:

None

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

None required.

Default Value:

This will depend on the CNI plugin in use.

See Also

https://workbench.cisecurity.org/benchmarks/14166