4.16 合规操作员基准

查看 Red Hat OpenShift on IBM Cloud 版本 4.16 的合规性操作员基准测试结果。

此版本已不再受支持。 请尽快将您的集群升级到 受支持的版本

1 控制平面组件

1.1 主节点配置文件

主节点配置不是以文件集的形式存储的,因此 1.1 节中的规则不在合规操作员自动检查的范围内。

1.2 应用程序接口服务器

API 服务器的基准测试。
科室 建议 手动/自动 级别 结果
1.2.1 Ensure 确保匿名请求已获得授权。 Manual 1 Pass
1.2.2 Ensure 表明 --basic-auth-file 参数未设置。 Automated 1 Pass
1.2.3 Ensure 提示未设置 --token-auth-file 参数。 Automated 1 Pass
1.2.4 Use kubelet 连接使用 HTTPS。 Automated 1 Pass
1.2.5 Ensure 确保 kubelet 使用证书进行身份验证。 Automated 1 Not 已验证
1.2.6 Verify 确保 kubelet 的证书颁发机构已正确配置。 Automated 1 Pass
1.2.7 Ensure 表明 --authorization-mode 参数未设置为 AlwaysAllow Automated 1 Pass
1.2.8 Verify 确保已启用 Node 授权器。 Automated 1 Pass
1.2.9 Verify 确认已启用 RBAC。 Automated 1 Pass
1.2.10 Ensure 确保已启用 APIPriorityAndFairness 功能开关。 Manual 1 Pass
1.2.11 Ensure 显示,接入控制插件 AlwaysAdmit 未设置。 Automated 1 Pass
1.2.12 Ensure 提示接入控制插件 AlwaysPullImages 未启用。 Manual 1 Pass
1.2.13 Ensure 提示接入控制插件 SecurityContextDeny 未启用。 Manual 1 Pass
1.2.14 Ensure 确保已配置接入控制插件 ServiceAccount Automated 1 Pass
1.2.15 Ensure 确保已设置访问控制插件 NamespaceLifecycle Automated 1 Pass
1.2.16 Ensure 确保已设置访问控制插件 SecurityContextConstraint Automated 1 Pass
1.2.17 Ensure 确保已设置访问控制插件 NodeRestriction Automated 1 Pass
1.2.18 Ensure 提示 --insecure-bind-address 参数未设置。 Automated 1 Pass
1.2.19 Ensure 表明 --insecure-port 参数被设置为 0。 Automated 1 Not 已通过检查
1.2.20 Ensure 表明 --secure-port 参数未设为 0。 Automated 1 Pass
1.2.21 Ensure 表明 healthz 端点受 RBAC 保护。 Automated 1 Pass
1.2.22 Ensure 表明已设置 --audit-log-path 参数。 Automated 1 Pass
1.2.23 Ensure 审计日志会被转发到集群外部进行保留。[ 自动化 1 未检查](#ibm-remediations-and-explanations-416-co)
1.2.24 Ensure 确保 maximumRetainedFiles 参数设置为 10 或适当的值。[ 自动 1 未检查](#ibm-remediations-and-explanations-416-co)
1.2.25 Ensure 确保 maximumFileSizeMegabytes 参数设置为 100 或适当值。 [ 自动 1 未检查](#ibm-remediations-and-explanations-416-co)
1.2.26 Ensure 确保将 --request-timeout 参数设置为适当的值。 Automated 1 Pass
1.2.27 Ensure 确保将 --service-account-lookup 参数设置为 true。 Automated 1 Pass
1.2.28 Ensure,请确保 --service-account-key-file 参数已正确设置。 Automated 1 Pass
1.2.29 Ensure 请确保将 --etcd-certfile--etcd-keyfile 参数设置为适当的值。 Automated 1 Pass
1.2.30 Ensure,确保 --tls-cert-file--tls-private-key-file 参数已正确设置。 Automated 1 Pass
1.2.31 Ensure,确保将 --client-ca-file 参数设置为适当的值。 Automated 1 Pass
1.2.32 Ensure 请确保将 --etcd-cafile 参数设置为适当的值。 Automated 1 Pass
1.2.33 Ensure 确保将 --encryption-provider-config 参数设置为适当值。[ 手册 1 未检查](#ibm-remediations-and-explanations-416-co)
1.2.34 Ensure 确保加密提供程序已正确配置。[ 手动 1 未检查](#ibm-remediations-and-explanations-416-co)
1.2.35 Ensure 该 API 服务器仅使用强加密算法。 Manual 1 Pass

1.3 控制器管理器

控制器管理器的基准测试。
科室 建议 手动/自动 级别 结果
1.3.1 Ensure 确保垃圾回收已按要求配置。 Manual 1 Not 已检查
1.3.2 Ensure 该控制器管理器 healthz 的端点受 RBAC 保护。 Automated 1 Pass
1.3.3 Ensure 确保 --use-service-account-credentials 参数设置为 true。 Automated 1 Pass
1.3.4 Ensure 确保将 --service-account-private-key-file 参数设置为适当值。 Automated 1 Pass
1.3.5 Ensure 请确保将 --root-ca-file 参数设置为适当的值。 Automated 1 Pass
1.3.6 Ensure 确保 RotateKubeletServerCertificate 参数设置为true。 Automated 2 Pass
1.3.7 Ensure 表明 --bind-address 参数被设置为 127.0.0.1 Automated 1 Pass

1.4调度程序

调度器的基准测试。
科室 建议 手动/自动 级别 结果
1.4.1 Ensure 说明调度程序的 healthz 端点受 RBAC 保护。 Automated 1 Pass
1.4.2 Verify 说明调度程序 API 服务受身份验证和授权保护。 Automated 1 Pass

2 Etcd

etcd 的基准测试。
科室 建议 手动/自动 级别 结果
2.1 Ensure,请确保将 --cert-file--key-file 参数设置为适当值。 Automated 1 Pass
2.2 Ensure 确保 --client-cert-auth 参数设置为true。 Automated 1 Pass
2.3 Ensure 显示 --auto-tls 参数未设置为true。 Automated 1 Pass
2.4 Ensure 确保已正确设置 --peer-cert-file--peer-key-file 参数。 Automated 1 Pass
2.5 Ensure 确保将 --peer-client-cert-auth 参数设置为true。 Automated 1 Pass
2.6 Ensure 指出,--peer-auto-tls 参数未设置为true。 Automated 1 Pass
2.7 Ensure 显示,etcd 使用了唯一的证书颁发机构。[ 手动 2 未检查](#ibm-remediations-and-explanations-416-co)

3 控制平面配置

3.1 身份验证与授权

认证和授权基准。
科室 建议 手动/自动 级别 结果
不应将 3.1.1 Client 证书认证用于用户。 Manual 2 Pass

3.2登录

记录基准。
科室 建议 手动/自动 级别 结果
3.2.1 Ensure 该链接说明已创建了一个最简审计策略。 Automated 1 Pass
3.2.2 Ensure 确保审计策略涵盖关键的安全问题。 Manual 2 Pass

4 个工作节点

按照“使用合规性操作员”中的说明,对工作节点配置执行自动检查。

5 项政策

5.1 RBAC 和服务帐户

RBAC 和服务账户的基准测试。
科室 建议 手动/自动 级别 结果
5.1.1 Ensure 指出,cluster-admin 角色仅在必要时使用。 Manual 1 Pass
5.1.2 Minimize 访问机密信息。 Manual 1 Not 已检查
RolesClusterRoles 中使用了 5.1.3 Minimize 通配符。 Manual 1 Not 已通过检查
5.1.4 Minimize 用于创建 Pod 的访问权限。 Manual 1 Not 已勾选
5.1.5 Ensure 默认服务账户未被积极使用。 Automated 1 Not 已勾选
5.1.6 Ensure 确保仅在必要时挂载服务账户令牌。 Manual 1 Not 已勾选

5.2 Pod 安全策略

Pod 安全策略的基准。
科室 建议 手动/自动 级别 结果
5.2.1 Minimize 允许使用受保护的容器。 Manual 1 Not 已通过检查
5.2.2 Minimize 允许容器共享宿主进程的 ID 命名空间。 Automated 1 Not 已勾选
5.2.3 Minimize 允许容器共享主机 IPC 命名空间。 Automated 1 Not 已检查
5.2.4 Minimize 允许希望共享主机网络命名空间的容器加入。 Automated 1 Not 已勾选
5.2.5 Minimize 允许使用 allowPrivilegeEscalation 的容器。 Automated 1 Not 已通过验证
5.2.6 Minimize 允许使用根容器。 Manual 2 Not 已检查
5.2.7 Minimize 允许具有 NET_RAW 功能的容器进入。 Manual 1 Not 已勾选
5.2.8 Minimize 允许使用具有附加功能的容器。[ 手册 1 未检查](#ibm-remediations-and-explanations-416-co)
5.2.9 Minimize 允许接收已分配能力的容器。 Manual 2 Not 已勾选

5.3 网络策略和 CNI

网络策略和 CNI 的基准测试。
科室 建议 手动/自动 级别 结果
5.3.1 Ensure 确保所使用的 CNI 支持网络策略。 Manual 1 Pass
5.3.2 Ensure 确保所有命名空间都已定义网络策略。[ 自动化 2 未检查](#ibm-remediations-and-explanations-416-co)

5.4 秘密管理

保密管理基准。
科室 建议 手动/自动 级别 结果
5.4.1 Prefer 建议优先使用文件形式的密钥,而非环境变量形式的密钥。 Manual 1 Not 已核对
5.4.2 Consider 外部密钥存储。 Manual 2 Not 已勾选

5.5 可扩展的准入控制

可扩展准入控制基准。
科室 建议 手动/自动 级别 结果
5.5.1 Configure 通过图像控制器配置参数验证图像来源。 Manual 2 Not 已勾选

5.7 一般政策

一般政策的基准。
科室 建议 手动/自动 级别 结果
5.7.1 Create 使用命名空间在资源之间划分管理边界。 Manual 1 Not 已检查
5.7.2 Ensure 请确保在您的 Pod 定义中,seccomp 配置文件已设置为 docker/default。 Manual 2 Not 已通过验证
已为您的 Pod 和容器配置 5.7.3 Apply 安全上下文。 Manual 2 Not 已通过验证
不应使用默认命名空间 5.7.4 The。 Automated 2 Not 已通过验证

IBM 补救和解释

查看 IBM 上关于 CIS Benchmark 结果的信息。

IBM 修复和解释的详细信息。
部分 建议/说明
1.2.23 Red Hat OpenShift IBM Cloud 可选择启用 API 服务器审计。Kubernetes
1.2.24 Red Hat OpenShift IBM Cloud 上的 参数设置为 1。maximumRetainedFiles
1.2.25 Red Hat OpenShift IBM Cloud 上的 参数设置为 10。maximumFileSizeMegabytes
1.2.33 Red Hat OpenShift IBM Cloud 上的用户可以选择启用 密钥管理服务 (KMS) 提供商。Kubernetes
1.2.34 Red Hat OpenShift IBM Cloud 上的用户可以选择启用 密钥管理服务 (KMS) 提供商。Kubernetes
2.7 Red Hat OpenShift IBM Cloud 上为 配置唯一的证书颁发机构。etcd
5.2.8 Red Hat OpenShift IBM 云上安装自定义。SCCs
5.3.2 Red Hat OpenShift IBM Cloud 上定义了一套默认的 网络策略,还可以选择添加其他网络策略。Calico