4.21 合规操作员基准
查看 Red Hat OpenShift on IBM Cloud 版本的合规操作员基准结果 4.21。
1 控制平面组件
1.1 主节点配置文件
主节点配置不是以文件集的形式存储的,因此 1.1 节中的规则不在合规操作员自动检查的范围内。
1.2 API 服务器
| 节 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 1.2.1 | Ensure | Automated | 1 | Not checked |
| 1.2.2 | Use https 用于 kubelet 连接。 | Automated | 1 | Pass |
| 1.2.3 | Ensure kubelet 使用证书进行身份验证。 | Automated | 1 | Pass |
| 1.2.4 | Verify 以确保 kubelet 证书授权设置正确。 | Automated | 1 | Pass |
| 1.2.5 | Ensure --authorization-mode 参数未设置为。AlwaysAllow |
Automated | 1 | Pass |
| 1.2.6 | Verify 已启用 RBAC。 | Automated | 1 | Pass |
| 1.2.7 | Ensure APIPriorityAndFairness 功能门已启用。MET |
Manual | 1 | |
| 1.2.8 | Ensure 未设置接入控制插件 AlwaysAdmit。 |
Automated | 1 | Pass |
| 1.2.9 | Ensure 未设置接入控制插件 AlwaysPullImages。 |
Automated | 1 | Pass |
| 1.2.10 | Ensure 已设置接入控制插件 ServiceAccount。 |
Automated | 1 | Pass |
| 1.2.11 | Ensure 已设置接入控制插件 NamespaceLifecycle。 |
Automated | 1 | Pass |
| 1.2.12 | Ensure 已设置接入控制插件 SecurityContextConstraint。 |
Automated | 1 | Pass |
| 1.2.13 | Ensure 已设置接入控制插件 NodeRestriction。 |
Automated | 1 | Pass |
| 1.2.14 | Ensure --insecure-bind-address 参数未设置。 |
Automated | 1 | Pass |
| 1.2.15 | Ensure --insecure-port 参数设置为 0。MET |
Manual | 1 | |
| 1.2.16 | Ensure --secure-port 参数未设置为 0。 |
Automated | 1 | Pass |
| 1.2.17 | Ensure healthz 端点受 RBAC 保护。checked |
Automated | 1 | |
| 1.2.18 | Ensure --audit-log-path 参数被设置。 |
Automated | 1 | Pass |
| 1.2.19 | Ensure 将审计日志转发到群集之外进行保留。 | 自动 | 1 | 未 选中 |
| 1.2.20 | Ensure maximumRetainedFiles 参数设置为 或视情况而定。 |
自动 | 1 | 未 10 选中 |
| 1.2.21 | Configure Kubernetes API 服务器最大审计日志大小。 | Automated | 1 | Not checked |
| 1.2.22 | Ensure --request-timeout 参数被设置。 |
Automated | 1 | Pass |
| 1.2.23 | Ensure --service-account-lookup 参数设置为 true。 |
Automated | 1 | Pass |
| 1.2.24 | Ensure --service-account-key-file 参数的设置。 |
Automated | 1 | Pass |
| 1.2.25 | Ensure --etcd-certfile 和 参数设置适当。--etcd-keyfile |
Automated | 1 | Pass |
| 1.2.26 | Ensure --tls-cert-file 和 参数设置适当。--tls-private-key-file |
Automated | 1 | Pass |
| 1.2.27 | Ensure --client-ca-file 参数的设置。 |
Automated | 1 | Pass |
| 1.2.28 | Ensure --etcd-cafile 参数的设置。 |
Automated | 1 | Pass |
| 1.2.29 | Ensure 加密提供商已进行适当配置。 | 自动 | 1 | 未 选中 |
| 1.2.30 | Ensure API 服务器只使用强加密算法。 | Automated | 1 | Not checked |
| 1.2.31 | Ensure 不使用不支持的配置覆盖。 | Manual | 1 | Pass |
1.3 控制经理
| 节 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 1.3.1 | Ensure | Automated | 1 | Not checked |
| 1.3.2 | Ensure --use-service-account-credentials 参数设置为 true。 |
Automated | 1 | Pass |
| 1.3.3 | Ensure --service-account-private-key-file 参数的设置。 |
Automated | 1 | Pass |
| 1.3.4 | Ensure --root-ca-file 参数的设置。 |
Automated | 1 | Pass |
1.4 调度员
| 节 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 1.4.1 | Ensure 调度程序的 healthz 端点受 RBAC 保护。 |
Automated | 1 | Not checked |
| 1.4.2 | Verify 调度程序接口服务受 RBAC 保护。 | Automated | 1 | Not checked |
2 Etcd
| 节 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 2.1 | Ensure --cert-file 和 参数设置适当。--key-file |
Automated | 1 | Pass |
| 2.2 | Ensure --client-cert-auth 参数设置为 true。 |
Automated | 1 | Pass |
| 2.3 | Ensure --auto-tls 参数未设置为 true。 |
Automated | 1 | Pass |
| 2.4 | Ensure --peer-cert-file 和 参数设置适当。--peer-key-file |
Automated | 1 | Pass |
| 2.5 | Ensure --peer-client-cert-auth 参数设置为 true。 |
Automated | 1 | Pass |
| 2.6 | Ensure --peer-auto-tls 参数未设置为 true。 |
Automated | 1 | Pass |
| 2.7 | Ensure etcd 使用唯一的证书颁发机构。 | 自动 | 2 | 未 选中 |
3 控制平面配置
3.2 记录
| 节 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 3.2.1 | Ensure | Automated | 1 | Not checked |
| 3.2.2 | Ensure | Automated | 2 | Not checked |
4 个工作节点
4.1 工作节点配置文件
| 节 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 4.1.1 | Ensure kubelet 服务文件权限设置为 644 或更严格。 |
Automated | 1 | Pass |
| 4.1.2 | Ensure 将 kubelet 服务文件所有权设置为 root:root。 |
Automated | 1 | Pass |
| 4.1.3 | If proxy kube 代理配置文件存在,确保权限设置为 644 或更严格。 |
Automated | 1 | Not checked |
| 4.1.4 | If 代理 kubeconfig 文件存在,确保所有权设置为 root:root. |
Automated | 1 | Not checked |
| 4.1.5 | Ensure --kubeconfig 文件所有权设置为。`` kubelet.conf file permissions are set to 644 or more restrictive. |
Automated | 1 | Pass |
| 4.1.6 | Ensure that the --kubeconfig`` kubelet.conf root:root |
Automated | 1 | Pass |
| 4.1.7 | Ensure 证书授权文件权限设置为 644 或更严格。 |
Automated | 1 | Pass |
| 4.1.8 | Ensure 客户证书颁发机构的文件所有权设置为 root:root。 |
Automated | 1 | Pass |
| 4.1.9 | Ensure kubelet --config 配置文件的权限设置为 600 或更严格。 |
Automated | 1 | Pass |
| 4.1.10 | Ensure 将 kubelet 配置文件的所有权设置为 root:root。 |
Automated | 1 | Pass |
4.2 Kubelet
| 节 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 4.2.1 | Activate 根据情况在 OpenShift Container Platform 4 中收集垃圾。 | Automated | 1 | Pass |
| 4.2.2 | Ensure --anonymous-auth 参数设置为 false。 |
Automated | 1 | Pass |
| 4.2.3 | Ensure --authorization-mode 参数未设置为。AlwaysAllow |
Automated | 1 | Pass |
| 4.2.4 | Ensure --client-ca-file 参数的设置。 |
Automated | 1 | Pass |
| 4.2.5 | Verify 只读端口未使用或设置为 0。 | Automated | 1 | Pass |
| 4.2.6 | Ensure --streaming-connection-idle-timeout 参数未设置为 0。 |
Automated | 1 | Pass |
| 4.2.7 | Ensure --make-iptables-util-chains 参数设置为 true。 |
Automated | 1 | Pass |
| 4.2.8 | Ensure kubeAPIQPS [--event-qps] 参数设置为可确保适当捕获事件的级别。 |
Automated | 2 | Pass |
| 4.2.9 | Ensure --tls-cert-file 和 参数设置适当。--tls-private-key-file |
Automated | 1 | Pass |
| 4.2.10 | Ensure --rotate-certificates 参数未设置为 false。 |
Automated | 1 | Pass |
| 4.2.11 | Verify RotateKubeletServerCertificate 参数设置为 true。 |
Automated | 1 | Pass |
| 4.2.12 | Ensure Kubelet 只使用强加密密码。 | Automated | 1 | Pass |
5 项政策
5.1 RBAC 和服务账户
| 节 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 5.1.1 | Ensure 只有在需要时才使用群集管理员角色。 | Manual | 1 | MANUAL |
| 5.1.2 | Minimize 获取机密。 | Manual | 1 | MANUAL |
| 5.1.3 | Minimize 通配符在 Roles 和 ClusterRoles 中的使用。 |
Manual | 1 | MANUAL |
| 5.1.4 | Minimize 访问权限来创建 pod。 | Manual | 1 | MANUAL |
| 5.1.5 | Ensure 默认服务账户没有被频繁使用。 | Manual | 1 | MANUAL |
| 5.1.6 | Ensure 仅在必要时才安装服务帐户令牌。 | Manual | 1 | MANUAL |
5.2 安全环境限制
| 节 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 5.2.1 | Minimize 接纳特权集装箱。 | Manual | 1 | MANUAL |
| 5.2.2 | Minimize 希望共享主机进程 ID 命名空间的容器。 | Manual | 1 | MANUAL |
| 5.2.3 | Minimize 容器共享主机 IPC 命名空间。 | Manual | 1 | MANUAL |
| 5.2.4 | Minimize 容器共享主机网络命名空间。 | Manual | 1 | MANUAL |
| 5.2.5 | Minimize allowPrivilegeEscalation。 |
Manual | 1 | MANUAL |
| 5.2.6 | Minimize 接纳根容器。 | Manual | 2 | MANUAL |
| 5.2.7 | Minimize 接纳具有 NET_RAW 功能的容器。 | Manual | 1 | MANUAL |
| 5.2.8 | Minimize 接纳具有附加功能的容器。 | 自动 | 1 | 未 选中 |
| 5.2.9 | Minimize 接纳已分配功能的容器。 | Manual | 2 | MANUAL |
| 5.2.10 | Minimize 访问权限 安全上下文限制。 | Manual | 2 | MANUAL |
5.3 网络政策和 CNI
| 节 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 5.3.1 | Ensure 使用的 CNI 支持网络策略。 | Automated | 1 | Not checked |
| 5.3.2 | Ensure 所有命名空间都定义了网络策略。 | 手册 [ | ](#ibm-remediations-and-explanations-421-co) 2 | 手册 |
5.4 秘密管理
| 节 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 5.4.1 | Prefer 将秘密作为文件使用,而不是将秘密作为环境变量使用。 | Manual | 1 | MANUAL |
| 5.4.2 | Consider 外部秘密存储器。 | Manual | 2 | MANUAL |
5.5 可扩展的准入控制
| 节 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 5.5.1 | Configure 使用图像控制器配置参数进行图像验证。 | Automated | 2 | Not checked |
5.7 一般政策
| 节 | 建议 | 手动/自动 | 级别 | 结果 |
|---|---|---|---|---|
| 5.7.1 | Create 使用命名空间划分资源之间的管理界限。 | Manual | 1 | MANUAL |
| 5.7.2 | Ensure 在 pod 定义中将 seccomp 配置文件设置为 docker/default。 |
Manual | 2 | MANUAL |
| 5.7.3 | Apply 为 Pod 和容器提供安全内涵。 | Manual | 2 | MANUAL |
| 5.7.4 | The 不应使用默认命名空间。 | Manual | 2 | MANUAL |
IBM 补救和解释
| 章节 | 建议/解释 |
|---|---|
| 1.2.19 | Red Hat OpenShift on IBM Cloud 可以选择启用 Kubernetes API 服务器审计。 |
| 1.2.20 | Red Hat OpenShift on IBM Cloud 将 maximumRetainedFiles 参数设置为 1。 |
| 1.2.29 | Red Hat OpenShift on IBM Cloud 可以选择启用 Kubernetes Key Management Service (KMS) 提供商。 |
| 2.7 | Red Hat OpenShift on IBM Cloud 为 etcd 配置唯一的证书颁发机构。 |
| 5.2.8 | Red Hat OpenShift on IBM Cloud installs custom SCCs. |
| 5.3.2 | Red Hat OpenShift on IBM Cloud 已定义了一套默认的 Calico 网络策略,并可选择添加其他网络策略。 |