4.19 合规操作员基准

查看 Red Hat OpenShift on IBM Cloud 版本的合规操作员基准结果 4.19。

1 控制平面组件

1.1 主节点配置文件

主节点配置不是以文件集的形式存储的,因此 1.1 节中的规则不在合规操作员自动检查的范围内。

1.2 API 服务器

api 服务器的基准。
科室 建议 手动/自动 级别 结果
1.2.1 Ensure 授权匿名请求。 Manual 1 Pass
1.2.2 Ensure 未设置 --basic-auth-file 参数。 Automated 1 Pass
1.2.3 Ensure 未设置 --token-auth-file 参数。 Automated 1 Pass
1.2.4 Use https 用于 kubelet 连接。 Automated 1 Pass
1.2.5 Ensure,kubelet 使用证书进行身份验证。 Automated 1 Not 已检查
1.2.6 Verify 已对 kubelet 证书授权进行适当设置。 Automated 1 Pass
1.2.7 Ensure,即 --authorization-mode 参数未设置为 AlwaysAllow Automated 1 Pass
1.2.8 Verify Node 授权器已启用。 Automated 1 Pass
1.2.9 Verify 已启用 RBAC。 Automated 1 Pass
1.2.10 Ensure APIPriorityAndFairness 功能门已启用。 Manual 1 Pass
1.2.11 Ensure 未设置接纳控制插件 AlwaysAdmit Automated 1 Pass
1.2.12 Ensure 未设置接纳控制插件 AlwaysPullImages Manual 1 Pass
1.2.13 Ensure 未设置接纳控制插件 SecurityContextDeny Manual 1 Pass
1.2.14 Ensure 已设置接入控制插件 ServiceAccount Automated 1 Pass
1.2.15 Ensure 已设置接入控制插件 NamespaceLifecycle Automated 1 Pass
1.2.16 Ensure 已设置接入控制插件 SecurityContextConstraint Automated 1 Pass
1.2.17 Ensure 已设置接入控制插件 NodeRestriction Automated 1 Pass
1.2.18 Ensure 未设置 --insecure-bind-address 参数。 Automated 1 Pass
1.2.19 Ensure,--insecure-port 参数设置为 0。 Automated 1 Not 已检查
1.2.20 Ensure --secure-port 参数未设置为 0。 Automated 1 Pass
1.2.21 Ensure healthz 端点受 RBAC 保护。 Automated 1 Pass
1.2.22 Ensure 已设置 --audit-log-path 参数。 Automated 1 Pass
1.2.23 Ensure 将审计日志转发到群集外保留。 自动 1 选中
1.2.24 Ensure,将 maximumRetainedFiles 参数设置为 10 或视情况而定。 自动 1 选中
1.2.25 Ensure,将 maximumFileSizeMegabytes 参数设置为 100 或视情况而定。 自动 1 选中
1.2.26 Ensure 设置了 --request-timeout 参数。 Automated 1 Pass
1.2.27 Ensure 参数 --service-account-lookup 设置为 true。 Automated 1 Pass
1.2.28 Ensure 设置了 --service-account-key-file 参数。 Automated 1 Pass
1.2.29 Ensure 根据需要设置 --etcd-certfile--etcd-keyfile 参数。 Automated 1 Pass
1.2.30 Ensure 根据需要设置 --tls-cert-file--tls-private-key-file 参数。 Automated 1 Pass
1.2.31 Ensure 设置了 --client-ca-file 参数。 Automated 1 Pass
1.2.32 Ensure 设置了 --etcd-cafile 参数。 Automated 1 Pass
1.2.33 Ensure 根据情况设置 --encryption-provider-config 参数。 手动 1 选中
1.2.34 Ensure 已适当配置加密提供程序。 手动 1 选中
1.2.35 Ensure,API 服务器只使用强加密密码。 Manual 1 Pass

1.3 控制经理

控制器管理器的基准。
科室 建议 手动/自动 级别 结果
1.3.1 Ensure 垃圾收集已按适当方式配置。 Manual 1 Not 已检查
1.3.2 Ensure 控制器管理器 healthz 端点受 RBAC 保护。 Automated 1 Pass
1.3.3 Ensure 参数 --use-service-account-credentials 设置为 true。 Automated 1 Pass
1.3.4 Ensure 设置了 --service-account-private-key-file 参数。 Automated 1 Pass
1.3.5 Ensure 设置了 --root-ca-file 参数。 Automated 1 Pass
1.3.6 Ensure 参数 RotateKubeletServerCertificate 设置为 true。 Automated 2 Pass
1.3.7 Ensure,即 --bind-address 参数设置为 127.0.0.1 Automated 1 Pass

1.4 调度员

调度程序的基准。
科室 建议 手动/自动 级别 结果
1.4.1 Ensure 调度程序的 healthz 端点受 RBAC 保护。 Automated 1 Pass
1.4.2 Verify 调度器 API 服务受身份验证和授权保护。 Automated 1 Pass

2 Etcd

etcd 的基准。
科室 建议 手动/自动 级别 结果
2.1 Ensure 根据需要设置 --cert-file--key-file 参数。 Automated 1 Pass
2.2 Ensure 参数 --client-cert-auth 设置为 true。 Automated 1 Pass
2.3 Ensure 参数 --auto-tls 未设置为 true。 Automated 1 Pass
2.4 Ensure 根据需要设置 --peer-cert-file--peer-key-file 参数。 Automated 1 Pass
2.5 Ensure 参数 --peer-client-cert-auth 设置为 true。 Automated 1 Pass
2.6 Ensure 参数 --peer-auto-tls 未设置为 true。 Automated 1 Pass
2.7 Ensure etcd 使用唯一的证书颁发机构。 手册 2 选中

3 控制平面配置

3.1 认证和授权

认证和授权基准。
科室 建议 手动/自动 级别 结果
3.1.1 Client 不应对用户使用证书验证。 Manual 2 Pass

3.2 记录

记录基准。
科室 建议 手动/自动 级别 结果
3.2.1 Ensure 已创建最小审计策略。 Automated 1 Pass
3.2.2 Ensure 审计政策涵盖主要安全问题。 Manual 2 Pass

4 个工作节点

按照“使用合规性操作员”中的说明,对工作节点配置执行自动检查。

5 项政策

5.1 RBAC 和服务账户

净资产收益率和服务账户基准。
科室 建议 手动/自动 级别 结果
5.1.1 Ensure 仅在需要时使用群集管理员角色。 Manual 1 Pass
5.1.2 Minimize 访问机密。 Manual 1 Not 已检查
5.1.3 Minimize 通配符在 RolesClusterRoles 中使用。 Manual 1 Not 已被检查
5.1.4 Minimize 访问创建 pod 的权限。 Manual 1 Not 已选中
5.1.5 Ensure,默认服务帐户未被激活使用。 Automated 1 Not 已检查
5.1.6 Ensure 仅在必要时安装服务帐户令牌。 Manual 1 Not 已选中

5.2 Pod 安全政策

pod 安全政策的基准。
科室 建议 手动/自动 级别 结果
5.2.1 Minimize 允许特权容器进入。 Manual 1 Not 已检查
5.2.2 Minimize 希望共享主机进程 ID 命名空间的容器的接纳。 Automated 1 Not 已选中
5.2.3 Minimize 允许希望共享主机 IPC 命名空间的容器进入。 Automated 1 Not 已检查
5.2.4 Minimize 希望共享主机网络命名空间的容器的接纳。 Automated 1 Not 已选中
5.2.5 Minimize 容器的接纳,allowPrivilegeEscalation Automated 1 Not 已检查
5.2.6 Minimize 允许根容器进入。 Manual 2 Not 已检查
5.2.7 Minimize 允许具有 NET_RAW 功能的容器进入。 Manual 1 Not 已检查
5.2.8 Minimize 允许具有附加功能的容器进入。 手动 1 选中
5.2.9 Minimize 允许已分配功能的容器进入。 Manual 2 Not 已检查

5.3 网络政策和 CNI

网络政策和 CNI 的基准。
科室 建议 手动/自动 级别 结果
5.3.1 Ensure 所用 CNI 支持网络策略。 Manual 1 Pass
5.3.2 Ensure 所有命名空间都定义了网络策略。 自动 2 选中

5.4 秘密管理

保密管理基准。
科室 建议 手动/自动 级别 结果
5.4.1 Prefer 使用秘密作为文件,而不是秘密作为环境变量。 Manual 1 Not 已检查
5.4.2 Consider 外部秘密存储器。 Manual 2 Not 已检查

5.5 可扩展的准入控制

可扩展准入控制基准。
科室 建议 手动/自动 级别 结果
5.5.1 Configure 使用图像控制器配置参数的图像证明。 Manual 2 Not 已检查

5.7 一般政策

一般政策的基准。
科室 建议 手动/自动 级别 结果
5.7.1 Create 使用命名空间划分资源之间的行政边界。 Manual 1 Not 已检查
5.7.2 Ensure,在 pod 定义中将 seccomp 配置文件设置为 docker/default。 Manual 2 Not 已检查
5.7.3 Apply Pod 和容器的安全上下文。 Manual 2 Not 已检查
5.7.4 The 不应使用默认命名空间。 Automated 2 Not 已检查

IBM 补救和解释

查看 IBM 上关于 CIS Benchmark 结果的信息。

IBM 修复和解释的详细信息。
部分 建议/说明
1.2.23 Red Hat OpenShift IBM Cloud 可选择启用 API 服务器审计。Kubernetes
1.2.24 Red Hat OpenShift IBM Cloud 上的 参数设置为 1。maximumRetainedFiles
1.2.25 Red Hat OpenShift IBM Cloud 上的 参数设置为 10。maximumFileSizeMegabytes
1.2.33 Red Hat OpenShift IBM Cloud 上的用户可以选择启用 密钥管理服务 (KMS) 提供商。Kubernetes
1.2.34 Red Hat OpenShift IBM Cloud 上的用户可以选择启用 密钥管理服务 (KMS) 提供商。Kubernetes
2.7 Red Hat OpenShift IBM Cloud 上为 配置唯一的证书颁发机构。etcd
5.2.8 Red Hat OpenShift IBM 云上安装自定义。SCCs
5.3.2 Red Hat OpenShift IBM Cloud 上定义了一套默认的 网络策略,还可以选择添加其他网络策略。Calico