3 | P a g e
1.1.11 Ensure that the etcd data directory permissions are set to 700 or more
restrictive (Automated) ................................................................................................................. 36
1.1.12 Ensure that the etcd data directory ownership is set to etcd:etcd
(Automated) ....................................................................................................................................... 38
1.1.13 Ensure that the admin.conf file permissions are set to 644 or more
restrictive (Automated) ................................................................................................................. 40
1.1.14 Ensure that the admin.conf file ownership is set to root:root (Automated)
.................................................................................................................................................................. 42
1.1.15 Ensure that the scheduler.conf file permissions are set to 644 or more
restrictive (Automated) ................................................................................................................. 44
1.1.16 Ensure that the scheduler.conf file ownership is set to root:root
(Automated) ....................................................................................................................................... 46
1.1.17 Ensure that the controller-manager.conf file permissions are set to 644 or
more restrictive (Automated) ..................................................................................................... 48
1.1.18 Ensure that the controller-manager.conf file ownership is set to root:root
(Automated) ....................................................................................................................................... 50
1.1.19 Ensure that the Kubernetes PKI directory and file ownership is set to
root:root (Automated) ................................................................................................................... 52
1.1.20 Ensure that the Kubernetes PKI certificate file permissions are set to 644
or more restrictive (Manual) ....................................................................................................... 54
1.1.21 Ensure that the Kubernetes PKI key file permissions are set to 600
(Manual) ............................................................................................................................................... 56
1.2 API Server .............................................................................................................................................. 58
1.2.1 Ensure that the --anonymous-auth argument is set to false (Manual) ............ 58
1.2.2 Ensure that the --token-auth-file parameter is not set (Automated) ............... 60
1.2.3 Ensure that the --kubelet-https argument is set to true (Automated) ............ 62
1.2.4 Ensure that the --kubelet-client-certificate and --kubelet-client-key
arguments are set as appropriate (Automated) .................................................................. 64
1.2.5 Ensure that the --kubelet-certificate-authority argument is set as
appropriate (Automated).............................................................................................................. 66
1.2.6 Ensure that the --authorization-mode argument is not set to AlwaysAllow
(Automated) ....................................................................................................................................... 68
1.2.7 Ensure that the --authorization-mode argument includes Node (Automated)
.................................................................................................................................................................. 70