Under active development Content is continuously updated and improved
Home / Frameworks / Kubernetes STIG / kubelet — Kubelet

kubelet Kubelet

23 findings in the Kubelet component

V-242387The Kubernetes Kubelet must have the "readOnlyPort" flag disabled.
V-242391The Kubernetes Kubelet must have anonymous authentication disabled.
V-242392The Kubernetes kubelet must enable explicit authorization.
V-242397The Kubernetes kubelet staticPodPath must not enable static pods.
V-242398Kubernetes DynamicAuditing must not be enabled.
V-242399Kubernetes DynamicKubeletConfig must not be enabled.
V-242404Kubernetes Kubelet must deny hostname override.
V-242406The Kubernetes KubeletConfiguration file must be owned by root.
V-242407The Kubernetes KubeletConfiguration files must have file permissions set to 644 or more restrictive.
V-242420Kubernetes Kubelet must have the SSL Certificate Authority set.
V-242424Kubernetes Kubelet must enable tlsPrivateKeyFile for client authentication to secure service.
V-242425Kubernetes Kubelet must enable tlsCertFile for client authentication to secure service.
V-242434Kubernetes Kubelet must enable kernel protection.
V-242449The Kubernetes Kubelet certificate authority file must have file permissions set to 644 or more restrictive.
V-242450The Kubernetes Kubelet certificate authority must be owned by root.
V-242452The Kubernetes kubelet KubeConfig must have file permissions set to 644 or more restrictive.
V-242453The Kubernetes kubelet KubeConfig file must be owned by root.
V-242454The Kubernetes kubeadm.conf must be owned by root.
V-242455The Kubernetes kubeadm.conf must have file permissions set to 644 or more restrictive.
V-242456The Kubernetes kubelet config must have file permissions set to 644 or more restrictive.
V-242457The Kubernetes kubelet config must be owned by root.
V-245541Kubernetes Kubelet must not disable timeouts.
V-254801Kubernetes must enable PodSecurity admission controller on static pods and Kubelets.