4.21 合规操作员基准

查看 Red Hat OpenShift on IBM Cloud 版本的合规操作员基准结果 4.21。

1 控制平面组件

1.1 主节点配置文件

主节点配置不是以文件集的形式存储的,因此 1.1 节中的规则不在合规操作员自动检查的范围内。

1.2 API 服务器

api 服务器的基准。
建议 手动/自动 级别 结果
1.2.1 Ensure Automated 1 Not checked
1.2.2 Use https 用于 kubelet 连接。 Automated 1 Pass
1.2.3 Ensure kubelet 使用证书进行身份验证。 Automated 1 Pass
1.2.4 Verify 以确保 kubelet 证书授权设置正确。 Automated 1 Pass
1.2.5 Ensure --authorization-mode 参数未设置为。AlwaysAllow Automated 1 Pass
1.2.6 Verify 已启用 RBAC。 Automated 1 Pass
1.2.7 Ensure APIPriorityAndFairness 功能门已启用。MET Manual 1
1.2.8 Ensure 未设置接入控制插件 AlwaysAdmit Automated 1 Pass
1.2.9 Ensure 未设置接入控制插件 AlwaysPullImages Automated 1 Pass
1.2.10 Ensure 已设置接入控制插件 ServiceAccount Automated 1 Pass
1.2.11 Ensure 已设置接入控制插件 NamespaceLifecycle Automated 1 Pass
1.2.12 Ensure 已设置接入控制插件 SecurityContextConstraint Automated 1 Pass
1.2.13 Ensure 已设置接入控制插件 NodeRestriction Automated 1 Pass
1.2.14 Ensure --insecure-bind-address 参数未设置。 Automated 1 Pass
1.2.15 Ensure --insecure-port 参数设置为 0。MET Manual 1
1.2.16 Ensure --secure-port 参数未设置为 0。 Automated 1 Pass
1.2.17 Ensure healthz 端点受 RBAC 保护。checked Automated 1
1.2.18 Ensure --audit-log-path 参数被设置。 Automated 1 Pass
1.2.19 Ensure 将审计日志转发到群集之外进行保留。 自动 1 选中
1.2.20 Ensure maximumRetainedFiles 参数设置为 或视情况而定。 自动 1 10 选中
1.2.21 Configure Kubernetes API 服务器最大审计日志大小。 Automated 1 Not checked
1.2.22 Ensure --request-timeout 参数被设置。 Automated 1 Pass
1.2.23 Ensure --service-account-lookup 参数设置为 true。 Automated 1 Pass
1.2.24 Ensure --service-account-key-file 参数的设置。 Automated 1 Pass
1.2.25 Ensure --etcd-certfile 和 参数设置适当。--etcd-keyfile Automated 1 Pass
1.2.26 Ensure --tls-cert-file 和 参数设置适当。--tls-private-key-file Automated 1 Pass
1.2.27 Ensure --client-ca-file 参数的设置。 Automated 1 Pass
1.2.28 Ensure --etcd-cafile 参数的设置。 Automated 1 Pass
1.2.29 Ensure 加密提供商已进行适当配置。 自动 1 选中
1.2.30 Ensure API 服务器只使用强加密算法。 Automated 1 Not checked
1.2.31 Ensure 不使用不支持的配置覆盖。 Manual 1 Pass

1.3 控制经理

控制器管理器的基准。
建议 手动/自动 级别 结果
1.3.1 Ensure Automated 1 Not checked
1.3.2 Ensure --use-service-account-credentials 参数设置为 true。 Automated 1 Pass
1.3.3 Ensure --service-account-private-key-file 参数的设置。 Automated 1 Pass
1.3.4 Ensure --root-ca-file 参数的设置。 Automated 1 Pass

1.4 调度员

调度程序的基准。
建议 手动/自动 级别 结果
1.4.1 Ensure 调度程序的 healthz 端点受 RBAC 保护。 Automated 1 Not checked
1.4.2 Verify 调度程序接口服务受 RBAC 保护。 Automated 1 Not checked

2 Etcd

etcd 的基准。
建议 手动/自动 级别 结果
2.1 Ensure --cert-file 和 参数设置适当。--key-file Automated 1 Pass
2.2 Ensure --client-cert-auth 参数设置为 true。 Automated 1 Pass
2.3 Ensure --auto-tls 参数未设置为 true。 Automated 1 Pass
2.4 Ensure --peer-cert-file 和 参数设置适当。--peer-key-file Automated 1 Pass
2.5 Ensure --peer-client-cert-auth 参数设置为 true。 Automated 1 Pass
2.6 Ensure --peer-auto-tls 参数未设置为 true。 Automated 1 Pass
2.7 Ensure etcd 使用唯一的证书颁发机构。 自动 2 选中

3 控制平面配置

3.1 认证和授权

认证和授权基准。
建议 手动/自动 级别 结果
3.1.1 Client 用户不应使用证书验证。 Automated 2 Pass

3.2 记录

记录基准。
建议 手动/自动 级别 结果
3.2.1 Ensure Automated 1 Not checked
3.2.2 Ensure Automated 2 Not checked

4 个工作节点

4.1 工作节点配置文件

工作节点配置文件的基准。
建议 手动/自动 级别 结果
4.1.1 Ensure kubelet 服务文件权限设置为 644 或更严格。 Automated 1 Pass
4.1.2 Ensure 将 kubelet 服务文件所有权设置为 root:root Automated 1 Pass
4.1.3 If proxy kube 代理配置文件存在,确保权限设置为 644 或更严格。 Automated 1 Not checked
4.1.4 If 代理 kubeconfig 文件存在,确保所有权设置为 root:root. Automated 1 Not checked
4.1.5 Ensure --kubeconfig 文件所有权设置为。`` kubelet.conf file permissions are set to 644 or more restrictive. Automated 1 Pass
4.1.6 Ensure that the --kubeconfig`` kubelet.conf root:root Automated 1 Pass
4.1.7 Ensure 证书授权文件权限设置为 644 或更严格。 Automated 1 Pass
4.1.8 Ensure 客户证书颁发机构的文件所有权设置为 root:root Automated 1 Pass
4.1.9 Ensure kubelet --config 配置文件的权限设置为 600 或更严格。 Automated 1 Pass
4.1.10 Ensure 将 kubelet 配置文件的所有权设置为 root:root Automated 1 Pass

4.2 Kubelet

kubelet 的基准。
建议 手动/自动 级别 结果
4.2.1 Activate 根据情况在 OpenShift Container Platform 4 中收集垃圾。 Automated 1 Pass
4.2.2 Ensure --anonymous-auth 参数设置为 false。 Automated 1 Pass
4.2.3 Ensure --authorization-mode 参数未设置为。AlwaysAllow Automated 1 Pass
4.2.4 Ensure --client-ca-file 参数的设置。 Automated 1 Pass
4.2.5 Verify 只读端口未使用或设置为 0。 Automated 1 Pass
4.2.6 Ensure --streaming-connection-idle-timeout 参数未设置为 0。 Automated 1 Pass
4.2.7 Ensure --make-iptables-util-chains 参数设置为 true。 Automated 1 Pass
4.2.8 Ensure kubeAPIQPS [--event-qps] 参数设置为可确保适当捕获事件的级别。 Automated 2 Pass
4.2.9 Ensure --tls-cert-file 和 参数设置适当。--tls-private-key-file Automated 1 Pass
4.2.10 Ensure --rotate-certificates 参数未设置为 false。 Automated 1 Pass
4.2.11 Verify RotateKubeletServerCertificate 参数设置为 true。 Automated 1 Pass
4.2.12 Ensure Kubelet 只使用强加密密码。 Automated 1 Pass

5 项政策

5.1 RBAC 和服务账户

净资产收益率和服务账户基准。
建议 手动/自动 级别 结果
5.1.1 Ensure 只有在需要时才使用群集管理员角色。 Manual 1 MANUAL
5.1.2 Minimize 获取机密。 Manual 1 MANUAL
5.1.3 Minimize 通配符在 RolesClusterRoles 中的使用。 Manual 1 MANUAL
5.1.4 Minimize 访问权限来创建 pod。 Manual 1 MANUAL
5.1.5 Ensure 默认服务账户没有被频繁使用。 Manual 1 MANUAL
5.1.6 Ensure 仅在必要时才安装服务帐户令牌。 Manual 1 MANUAL

5.2 安全环境限制

安全环境约束基准。
建议 手动/自动 级别 结果
5.2.1 Minimize 接纳特权集装箱。 Manual 1 MANUAL
5.2.2 Minimize 希望共享主机进程 ID 命名空间的容器。 Manual 1 MANUAL
5.2.3 Minimize 容器共享主机 IPC 命名空间。 Manual 1 MANUAL
5.2.4 Minimize 容器共享主机网络命名空间。 Manual 1 MANUAL
5.2.5 Minimize allowPrivilegeEscalation Manual 1 MANUAL
5.2.6 Minimize 接纳根容器。 Manual 2 MANUAL
5.2.7 Minimize 接纳具有 NET_RAW 功能的容器。 Manual 1 MANUAL
5.2.8 Minimize 接纳具有附加功能的容器。 自动 1 选中
5.2.9 Minimize 接纳已分配功能的容器。 Manual 2 MANUAL
5.2.10 Minimize 访问权限 安全上下文限制。 Manual 2 MANUAL

5.3 网络政策和 CNI

网络政策和 CNI 的基准。
建议 手动/自动 级别 结果
5.3.1 Ensure 使用的 CNI 支持网络策略。 Automated 1 Not checked
5.3.2 Ensure 所有命名空间都定义了网络策略。 手册 [ ](#ibm-remediations-and-explanations-421-co) 2 手册

5.4 秘密管理

保密管理基准。
建议 手动/自动 级别 结果
5.4.1 Prefer 将秘密作为文件使用,而不是将秘密作为环境变量使用。 Manual 1 MANUAL
5.4.2 Consider 外部秘密存储器。 Manual 2 MANUAL

5.5 可扩展的准入控制

可扩展准入控制基准。
建议 手动/自动 级别 结果
5.5.1 Configure 使用图像控制器配置参数进行图像验证。 Automated 2 Not checked

5.7 一般政策

一般政策的基准。
建议 手动/自动 级别 结果
5.7.1 Create 使用命名空间划分资源之间的管理界限。 Manual 1 MANUAL
5.7.2 Ensure 在 pod 定义中将 seccomp 配置文件设置为 docker/default。 Manual 2 MANUAL
5.7.3 Apply 为 Pod 和容器提供安全内涵。 Manual 2 MANUAL
5.7.4 The 不应使用默认命名空间。 Manual 2 MANUAL

IBM 补救和解释

IBM 补救和解释的详细信息
章节 建议/解释
1.2.19 Red Hat OpenShift on IBM Cloud 可以选择启用 Kubernetes API 服务器审计。
1.2.20 Red Hat OpenShift on IBM Cloud 将 maximumRetainedFiles 参数设置为 1。
1.2.29 Red Hat OpenShift on IBM Cloud 可以选择启用 Kubernetes Key Management Service (KMS) 提供商。
2.7 Red Hat OpenShift on IBM Cloud 为 etcd 配置唯一的证书颁发机构。
5.2.8 Red Hat OpenShift on IBM Cloud installs custom SCCs.
5.3.2 Red Hat OpenShift on IBM Cloud 已定义了一套默认的 Calico 网络策略,并可选择添加其他网络策略。