4.16 合规操作员基准
查看 Red Hat OpenShift on IBM Cloud 版本 4.16 的合规性操作员基准测试结果。
此版本已不再受支持。 请尽快将您的集群升级到 受支持的版本。
1 控制平面组件
1.1 主节点配置文件
主节点配置不是以文件集的形式存储的,因此 1.1 节中的规则不在合规操作员自动检查的范围内。
1.2 应用程序接口服务器
| 科室 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 1.2.1 | Ensure 确保匿名请求已获得授权。 | Manual | 1 | Pass |
| 1.2.2 | Ensure 表明 --basic-auth-file 参数未设置。 |
Automated | 1 | Pass |
| 1.2.3 | Ensure 提示未设置 --token-auth-file 参数。 |
Automated | 1 | Pass |
| 1.2.4 | Use kubelet 连接使用 HTTPS。 | Automated | 1 | Pass |
| 1.2.5 | Ensure 确保 kubelet 使用证书进行身份验证。 | Automated | 1 | Not 已验证 |
| 1.2.6 | Verify 确保 kubelet 的证书颁发机构已正确配置。 | Automated | 1 | Pass |
| 1.2.7 | Ensure 表明 --authorization-mode 参数未设置为 AlwaysAllow。 |
Automated | 1 | Pass |
| 1.2.8 | Verify 确保已启用 Node 授权器。 | Automated | 1 | Pass |
| 1.2.9 | Verify 确认已启用 RBAC。 | Automated | 1 | Pass |
| 1.2.10 | Ensure 确保已启用 APIPriorityAndFairness 功能开关。 |
Manual | 1 | Pass |
| 1.2.11 | Ensure 显示,接入控制插件 AlwaysAdmit 未设置。 |
Automated | 1 | Pass |
| 1.2.12 | Ensure 提示接入控制插件 AlwaysPullImages 未启用。 |
Manual | 1 | Pass |
| 1.2.13 | Ensure 提示接入控制插件 SecurityContextDeny 未启用。 |
Manual | 1 | Pass |
| 1.2.14 | Ensure 确保已配置接入控制插件 ServiceAccount。 |
Automated | 1 | Pass |
| 1.2.15 | Ensure 确保已设置访问控制插件 NamespaceLifecycle。 |
Automated | 1 | Pass |
| 1.2.16 | Ensure 确保已设置访问控制插件 SecurityContextConstraint。 |
Automated | 1 | Pass |
| 1.2.17 | Ensure 确保已设置访问控制插件 NodeRestriction。 |
Automated | 1 | Pass |
| 1.2.18 | Ensure 提示 --insecure-bind-address 参数未设置。 |
Automated | 1 | Pass |
| 1.2.19 | Ensure 表明 --insecure-port 参数被设置为 0。 |
Automated | 1 | Not 已通过检查 |
| 1.2.20 | Ensure 表明 --secure-port 参数未设为 0。 |
Automated | 1 | Pass |
| 1.2.21 | Ensure 表明 healthz 端点受 RBAC 保护。 |
Automated | 1 | Pass |
| 1.2.22 | Ensure 表明已设置 --audit-log-path 参数。 |
Automated | 1 | Pass |
| 1.2.23 | Ensure 审计日志会被转发到集群外部进行保留。[ | 自动化 | 1 | 未检查](#ibm-remediations-and-explanations-416-co) |
| 1.2.24 | Ensure 确保 maximumRetainedFiles 参数设置为 10 或适当的值。[ |
自动 | 1 | 未检查](#ibm-remediations-and-explanations-416-co) |
| 1.2.25 | Ensure 确保 maximumFileSizeMegabytes 参数设置为 100 或适当值。 [ |
自动 | 1 | 未检查](#ibm-remediations-and-explanations-416-co) |
| 1.2.26 | Ensure 确保将 --request-timeout 参数设置为适当的值。 |
Automated | 1 | Pass |
| 1.2.27 | Ensure 确保将 --service-account-lookup 参数设置为 true。 |
Automated | 1 | Pass |
| 1.2.28 | Ensure,请确保 --service-account-key-file 参数已正确设置。 |
Automated | 1 | Pass |
| 1.2.29 | Ensure 请确保将 --etcd-certfile 和 --etcd-keyfile 参数设置为适当的值。 |
Automated | 1 | Pass |
| 1.2.30 | Ensure,确保 --tls-cert-file 和 --tls-private-key-file 参数已正确设置。 |
Automated | 1 | Pass |
| 1.2.31 | Ensure,确保将 --client-ca-file 参数设置为适当的值。 |
Automated | 1 | Pass |
| 1.2.32 | Ensure 请确保将 --etcd-cafile 参数设置为适当的值。 |
Automated | 1 | Pass |
| 1.2.33 | Ensure 确保将 --encryption-provider-config 参数设置为适当值。[ |
手册 | 1 | 未检查](#ibm-remediations-and-explanations-416-co) |
| 1.2.34 | Ensure 确保加密提供程序已正确配置。[ | 手动 | 1 | 未检查](#ibm-remediations-and-explanations-416-co) |
| 1.2.35 | Ensure 该 API 服务器仅使用强加密算法。 | Manual | 1 | Pass |
1.3 控制器管理器
| 科室 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 1.3.1 | Ensure 确保垃圾回收已按要求配置。 | Manual | 1 | Not 已检查 |
| 1.3.2 | Ensure 该控制器管理器 healthz 的端点受 RBAC 保护。 |
Automated | 1 | Pass |
| 1.3.3 | Ensure 确保 --use-service-account-credentials 参数设置为 true。 |
Automated | 1 | Pass |
| 1.3.4 | Ensure 确保将 --service-account-private-key-file 参数设置为适当值。 |
Automated | 1 | Pass |
| 1.3.5 | Ensure 请确保将 --root-ca-file 参数设置为适当的值。 |
Automated | 1 | Pass |
| 1.3.6 | Ensure 确保 RotateKubeletServerCertificate 参数设置为true。 |
Automated | 2 | Pass |
| 1.3.7 | Ensure 表明 --bind-address 参数被设置为 127.0.0.1。 |
Automated | 1 | Pass |
1.4调度程序
| 科室 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 1.4.1 | Ensure 说明调度程序的 healthz 端点受 RBAC 保护。 |
Automated | 1 | Pass |
| 1.4.2 | Verify 说明调度程序 API 服务受身份验证和授权保护。 | Automated | 1 | Pass |
2 Etcd
| 科室 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 2.1 | Ensure,请确保将 --cert-file 和 --key-file 参数设置为适当值。 |
Automated | 1 | Pass |
| 2.2 | Ensure 确保 --client-cert-auth 参数设置为true。 |
Automated | 1 | Pass |
| 2.3 | Ensure 显示 --auto-tls 参数未设置为true。 |
Automated | 1 | Pass |
| 2.4 | Ensure 确保已正确设置 --peer-cert-file 和 --peer-key-file 参数。 |
Automated | 1 | Pass |
| 2.5 | Ensure 确保将 --peer-client-cert-auth 参数设置为true。 |
Automated | 1 | Pass |
| 2.6 | Ensure 指出,--peer-auto-tls 参数未设置为true。 |
Automated | 1 | Pass |
| 2.7 | Ensure 显示,etcd 使用了唯一的证书颁发机构。[ | 手动 | 2 | 未检查](#ibm-remediations-and-explanations-416-co) |
3 控制平面配置
3.2登录
| 科室 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 3.2.1 | Ensure 该链接说明已创建了一个最简审计策略。 | Automated | 1 | Pass |
| 3.2.2 | Ensure 确保审计策略涵盖关键的安全问题。 | Manual | 2 | Pass |
4 个工作节点
按照“使用合规性操作员”中的说明,对工作节点配置执行自动检查。
5 项政策
5.1 RBAC 和服务帐户
| 科室 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 5.1.1 | Ensure 指出,cluster-admin 角色仅在必要时使用。 | Manual | 1 | Pass |
| 5.1.2 | Minimize 访问机密信息。 | Manual | 1 | Not 已检查 |
在 Roles 和 ClusterRoles 中使用了 5.1.3 |
Minimize 通配符。 | Manual | 1 | Not 已通过检查 |
| 5.1.4 | Minimize 用于创建 Pod 的访问权限。 | Manual | 1 | Not 已勾选 |
| 5.1.5 | Ensure 默认服务账户未被积极使用。 | Automated | 1 | Not 已勾选 |
| 5.1.6 | Ensure 确保仅在必要时挂载服务账户令牌。 | Manual | 1 | Not 已勾选 |
5.2 Pod 安全策略
| 科室 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 5.2.1 | Minimize 允许使用受保护的容器。 | Manual | 1 | Not 已通过检查 |
| 5.2.2 | Minimize 允许容器共享宿主进程的 ID 命名空间。 | Automated | 1 | Not 已勾选 |
| 5.2.3 | Minimize 允许容器共享主机 IPC 命名空间。 | Automated | 1 | Not 已检查 |
| 5.2.4 | Minimize 允许希望共享主机网络命名空间的容器加入。 | Automated | 1 | Not 已勾选 |
| 5.2.5 | Minimize 允许使用 allowPrivilegeEscalation 的容器。 |
Automated | 1 | Not 已通过验证 |
| 5.2.6 | Minimize 允许使用根容器。 | Manual | 2 | Not 已检查 |
| 5.2.7 | Minimize 允许具有 NET_RAW 功能的容器进入。 | Manual | 1 | Not 已勾选 |
| 5.2.8 | Minimize 允许使用具有附加功能的容器。[ | 手册 | 1 | 未检查](#ibm-remediations-and-explanations-416-co) |
| 5.2.9 | Minimize 允许接收已分配能力的容器。 | Manual | 2 | Not 已勾选 |
5.3 网络策略和 CNI
| 科室 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 5.3.1 | Ensure 确保所使用的 CNI 支持网络策略。 | Manual | 1 | Pass |
| 5.3.2 | Ensure 确保所有命名空间都已定义网络策略。[ | 自动化 | 2 | 未检查](#ibm-remediations-and-explanations-416-co) |
5.4 秘密管理
| 科室 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 5.4.1 | Prefer 建议优先使用文件形式的密钥,而非环境变量形式的密钥。 | Manual | 1 | Not 已核对 |
| 5.4.2 | Consider 外部密钥存储。 | Manual | 2 | Not 已勾选 |
5.5 可扩展的准入控制
| 科室 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 5.5.1 | Configure 通过图像控制器配置参数验证图像来源。 | Manual | 2 | Not 已勾选 |
5.7 一般政策
| 科室 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 5.7.1 | Create 使用命名空间在资源之间划分管理边界。 | Manual | 1 | Not 已检查 |
| 5.7.2 | Ensure 请确保在您的 Pod 定义中,seccomp 配置文件已设置为 docker/default。 |
Manual | 2 | Not 已通过验证 |
| 已为您的 Pod 和容器配置 5.7.3 | Apply 安全上下文。 | Manual | 2 | Not 已通过验证 |
| 不应使用默认命名空间 5.7.4 | The。 | Automated | 2 | Not 已通过验证 |
IBM 补救和解释
查看 IBM 上关于 CIS Benchmark 结果的信息。
| 部分 | 建议/说明 |
|---|---|
| 1.2.23 | Red Hat OpenShift IBM Cloud 可选择启用 API 服务器审计。Kubernetes |
| 1.2.24 | Red Hat OpenShift IBM Cloud 上的 参数设置为 1。maximumRetainedFiles |
| 1.2.25 | Red Hat OpenShift IBM Cloud 上的 参数设置为 10。maximumFileSizeMegabytes |
| 1.2.33 | Red Hat OpenShift IBM Cloud 上的用户可以选择启用 密钥管理服务 (KMS) 提供商。Kubernetes |
| 1.2.34 | Red Hat OpenShift IBM Cloud 上的用户可以选择启用 密钥管理服务 (KMS) 提供商。Kubernetes |
| 2.7 | Red Hat OpenShift IBM Cloud 上为 配置唯一的证书颁发机构。etcd |
| 5.2.8 | Red Hat OpenShift IBM 云上安装自定义。SCCs |
| 5.3.2 | Red Hat OpenShift IBM Cloud 上定义了一套默认的 网络策略,还可以选择添加其他网络策略。Calico |