mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-09 21:14:22 +00:00
chore(kubernetes): enhance metadata for controllermanager service (#9675)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
This commit is contained in:
co-authored by
Daniel Barranquero
parent
6069d6e231
commit
5968441f59
@@ -7,6 +7,7 @@ All notable changes to the **Prowler SDK** are documented in this file.
|
||||
### 🔄 Changed
|
||||
|
||||
- Update Kubernetes API server checks metadata to new format [(#9674)](https://github.com/prowler-cloud/prowler/pull/9674)
|
||||
- Update Kubernetes Controller Manager service metadata to new format [(#9675)](https://github.com/prowler-cloud/prowler/pull/9675)
|
||||
|
||||
---
|
||||
|
||||
|
||||
+15
-11
@@ -1,30 +1,34 @@
|
||||
{
|
||||
"Provider": "kubernetes",
|
||||
"CheckID": "controllermanager_bind_address",
|
||||
"CheckTitle": "Ensure that the --bind-address argument is set to 127.0.0.1",
|
||||
"CheckTitle": "Controller Manager pod is bound to the loopback address 127.0.0.1",
|
||||
"CheckType": [],
|
||||
"ServiceName": "controllermanager",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "KubernetesControllerManager",
|
||||
"Severity": "high",
|
||||
"ResourceType": "Pod",
|
||||
"ResourceGroup": "container",
|
||||
"Description": "This check verifies that the Kubernetes Controller Manager is bound to the loopback address (127.0.0.1) to minimize the cluster's attack surface. Binding to the loopback address ensures that the Controller Manager API service is not exposed to unauthorized network access.",
|
||||
"Risk": "Binding the Controller Manager to a non-loopback address exposes sensitive health and metrics information without authentication or encryption.",
|
||||
"RelatedUrl": "https://kubernetes.io/docs/reference/command-line-tools-reference/kube-controller-manager/",
|
||||
"Description": "**Kubernetes controller manager** uses the **loopback bind address** `127.0.0.1` via `--bind-address` or `--address`, keeping its health, metrics, and debug endpoints reachable only from the host",
|
||||
"Risk": "Listening on a non-loopback address exposes **health**, **metrics**, and **debug** endpoints to the network, enabling control-plane **reconnaissance** and leakage of internal state. Heavy scraping or profiling can drive resource exhaustion, reducing control-plane **availability** and stability.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://kubernetes.io/docs/reference/command-line-tools-reference/kube-controller-manager/"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "--bind-address=127.0.0.1",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/kubernetes/kubernetes-policy-index/ensure-that-the-bind-address-argument-is-set-to-127001",
|
||||
"Other": "",
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "1. SSH to the control-plane node running the Controller Manager\n2. Edit the static Pod manifest: /etc/kubernetes/manifests/kube-controller-manager.yaml\n3. Under spec.containers[0] command/args, add the flag:\n - --bind-address=127.0.0.1\n4. Save the file; the kubelet will automatically restart the Pod with the new setting",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Bind the Controller Manager to the loopback address for enhanced security.",
|
||||
"Url": "https://kubernetes.io/docs/reference/command-line-tools-reference/kube-controller-manager/"
|
||||
"Text": "Bind to `127.0.0.1` and apply **defense in depth**:\n- Prefer local-only endpoints; avoid `0.0.0.0`\n- Use **TLS** and authentication if exposure is unavoidable\n- Enforce **network segmentation** for control-plane access\n- Disable profiling when not needed; apply **least privilege** for telemetry",
|
||||
"Url": "https://hub.prowler.com/check/controllermanager_bind_address"
|
||||
}
|
||||
},
|
||||
"Categories": [
|
||||
"cluster-security",
|
||||
"internet-exposed"
|
||||
],
|
||||
"DependsOn": [],
|
||||
|
||||
+14
-11
@@ -1,31 +1,34 @@
|
||||
{
|
||||
"Provider": "kubernetes",
|
||||
"CheckID": "controllermanager_disable_profiling",
|
||||
"CheckTitle": "Ensure that the --profiling argument is set to false",
|
||||
"CheckTitle": "Controller Manager pod has --profiling=false configured",
|
||||
"CheckType": [],
|
||||
"ServiceName": "controllermanager",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "KubernetesControllerManager",
|
||||
"ResourceType": "Pod",
|
||||
"ResourceGroup": "container",
|
||||
"Description": "This check ensures that profiling is disabled in the Kubernetes Controller Manager, reducing the potential attack surface.",
|
||||
"Risk": "Enabling profiling can expose detailed system and program information, which could be exploited if accessed by unauthorized users.",
|
||||
"RelatedUrl": "https://kubernetes.io/docs/reference/command-line-tools-reference/kube-controller-manager/",
|
||||
"Description": "**Kubernetes Controller Manager** is evaluated for the `--profiling` argument. `--profiling=false` disables runtime profiling; absence or a different value means profiling is enabled.",
|
||||
"Risk": "With profiling enabled, debug endpoints expose **runtime internals** (stacks, memory, file paths), weakening confidentiality. Abusing profiling can raise CPU/memory use and degrade **availability**. Detailed insights accelerate reconnaissance and can aid escalation when combined with RBAC gaps.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://kubernetes.io/docs/reference/command-line-tools-reference/kube-controller-manager/#options"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "--profiling=false",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/kubernetes/kubernetes-policy-index/ensure-that-the-profiling-argument-is-set-to-false",
|
||||
"Other": "",
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "1. SSH to each control plane node\n2. Open /etc/kubernetes/manifests/kube-controller-manager.yaml\n3. Under spec.containers[0].command add the line: - --profiling=false\n4. Save the file; kubelet will automatically restart the static Pod\n5. Verify on the node: ps -ef | grep kube-controller-manager | grep -- --profiling=false",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Disable profiling in the Kubernetes Controller Manager for enhanced security.",
|
||||
"Url": "https://kubernetes.io/docs/reference/command-line-tools-reference/kube-controller-manager/#options"
|
||||
"Text": "Set `--profiling=false` on the **controller manager** to remove debug endpoints.\n\n*If profiling is needed temporarily*:\n- Limit access using **least privilege** and network controls\n- Use isolated environments and monitor closely\n- Disable promptly to uphold **defense in depth**",
|
||||
"Url": "https://hub.prowler.com/check/controllermanager_disable_profiling"
|
||||
}
|
||||
},
|
||||
"Categories": [
|
||||
"trustboundaries"
|
||||
"cluster-security"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
|
||||
+15
-11
@@ -1,27 +1,31 @@
|
||||
{
|
||||
"Provider": "kubernetes",
|
||||
"CheckID": "controllermanager_garbage_collection",
|
||||
"CheckTitle": "Ensure that the --terminated-pod-gc-threshold argument is set as appropriate",
|
||||
"CheckTitle": "Controller Manager pod does not use the default --terminated-pod-gc-threshold value",
|
||||
"CheckType": [],
|
||||
"ServiceName": "controllermanager",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "KubernetesControllerManager",
|
||||
"Severity": "high",
|
||||
"ResourceType": "Pod",
|
||||
"ResourceGroup": "container",
|
||||
"Description": "Activate garbage collector on pod termination, as appropriate. Garbage collection is crucial for maintaining resource availability and performance. The default threshold for garbage collection is 12,500 terminated pods, which may be too high for some systems. Adjusting this threshold based on system resources and performance tests is recommended.",
|
||||
"Risk": "A high threshold for garbage collection can lead to degraded performance and resource exhaustion. In extreme cases, it might cause system crashes or prolonged unavailability.",
|
||||
"RelatedUrl": "https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/#pod-garbage-collection",
|
||||
"Description": "**Kubernetes controller manager** terminated Pod garbage collection threshold is evaluated. The finding highlights use of the default `--terminated-pod-gc-threshold=12500` instead of a value tuned to cluster size and workload churn. The threshold controls when terminated Pods are automatically removed.",
|
||||
"Risk": "Retaining too many terminated Pods strains **API server**, **etcd**, and controller memory, reducing control-plane **availability**. Effects include slow list/watch operations, lagging schedulers, timeouts, and, in worst cases, controller crashes or admin-plane DoS.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://kubernetes.io/docs/concepts/workloads/pods/pod-lifecycle/#pod-garbage-collection",
|
||||
"https://kubernetes.io/docs/reference/command-line-tools-reference/kube-controller-manager/"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "--terminated-pod-gc-threshold=10",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/kubernetes/kubernetes-policy-index/ensure-that-the-terminated-pod-gc-threshold-argument-is-set-as-appropriate",
|
||||
"Other": "",
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "1. SSH to each control-plane node\n2. Edit the static Pod manifest: /etc/kubernetes/manifests/kube-controller-manager.yaml\n3. Under the kube-controller-manager container args/command, set: --terminated-pod-gc-threshold=10 (any value not equal to 12500)\n4. Save the file; the kubelet will automatically restart the controller-manager\n5. Repeat on all control-plane nodes if using HA",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Review and adjust the --terminated-pod-gc-threshold argument in the kube-controller-manager to ensure efficient garbage collection and optimal resource utilization.",
|
||||
"Url": "https://kubernetes.io/docs/reference/command-line-tools-reference/kube-controller-manager/"
|
||||
"Text": "Set a **lower, context-appropriate** `--terminated-pod-gc-threshold` to match cluster scale and pod churn, preserving control-plane capacity. Monitor garbage collection and control-plane metrics and adjust proactively. Use `ttlSecondsAfterFinished` for Jobs to minimize terminated Pods.",
|
||||
"Url": "https://hub.prowler.com/check/controllermanager_garbage_collection"
|
||||
}
|
||||
},
|
||||
"Categories": [
|
||||
|
||||
+15
-12
@@ -1,32 +1,35 @@
|
||||
{
|
||||
"Provider": "kubernetes",
|
||||
"CheckID": "controllermanager_root_ca_file_set",
|
||||
"CheckTitle": "Ensure that the --root-ca-file argument is set as appropriate",
|
||||
"CheckTitle": "Controller Manager pod has --root-ca-file argument set",
|
||||
"CheckType": [],
|
||||
"ServiceName": "controllermanager",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "KubernetesControllerManager",
|
||||
"Severity": "critical",
|
||||
"ResourceType": "Pod",
|
||||
"ResourceGroup": "container",
|
||||
"Description": "This check verifies that the Kubernetes Controller Manager is configured with the --root-ca-file argument set to a certificate bundle file, allowing pods to verify the API server's serving certificate.",
|
||||
"Risk": "Not setting the root CA file can expose pods to man-in-the-middle attacks due to unverified TLS connections to the API server.",
|
||||
"RelatedUrl": "https://kubernetes.io/docs/setup/best-practices/certificates/",
|
||||
"Description": "**Kubernetes Controller Manager** uses `--root-ca-file` to reference a certificate bundle so pods get a `ca.crt` for validating the API server's TLS certificate.",
|
||||
"Risk": "Without a configured root CA, pods cannot reliably verify the API server, enabling on-path spoofing. This exposes API traffic and service account tokens, allowing session hijack, data exfiltration, and malicious config changes-compromising confidentiality and integrity, and potentially disrupting availability.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://kubernetes.io/docs/setup/best-practices/certificates/#certificate-paths"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "--root-ca-file=/path/to/ca-file",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/kubernetes/kubernetes-policy-index/ensure-that-the-root-ca-file-argument-is-set-as-appropriate",
|
||||
"Other": "",
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "1. SSH to a control-plane node with sudo privileges\n2. Edit the static Pod manifest: /etc/kubernetes/manifests/kube-controller-manager.yaml\n3. In the kube-controller-manager container command list, add this flag:\n - --root-ca-file=/etc/kubernetes/pki/ca.crt\n4. Save the file; kubelet will automatically restart the Pod",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Configure the Controller Manager with a root CA file to enhance security for pods communicating with the API server.",
|
||||
"Url": "https://kubernetes.io/docs/setup/best-practices/certificates/#certificate-paths"
|
||||
"Text": "Set a trusted CA bundle via `--root-ca-file` on the controller manager to ensure verified TLS for in-cluster API calls. Use a cluster-controlled CA, rotate and monitor certificates, and keep the bundle aligned with the API server chain. Apply **defense in depth** and **least privilege** for service accounts.",
|
||||
"Url": "https://hub.prowler.com/check/controllermanager_root_ca_file_set"
|
||||
}
|
||||
},
|
||||
"Categories": [
|
||||
"encryption",
|
||||
"internet-exposed"
|
||||
"cluster-security"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
|
||||
+15
-11
@@ -1,31 +1,35 @@
|
||||
{
|
||||
"Provider": "kubernetes",
|
||||
"CheckID": "controllermanager_rotate_kubelet_server_cert",
|
||||
"CheckTitle": "Ensure that the RotateKubeletServerCertificate argument is set to true",
|
||||
"CheckTitle": "Controller Manager pod has RotateKubeletServerCertificate set to true",
|
||||
"CheckType": [],
|
||||
"ServiceName": "controllermanager",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "KubernetesControllerManager",
|
||||
"ResourceType": "Pod",
|
||||
"ResourceGroup": "container",
|
||||
"Description": "This check ensures that the Kubernetes Controller Manager is configured with the RotateKubeletServerCertificate argument set to true, enabling automated rotation of kubelet server certificates.",
|
||||
"Risk": "Not enabling kubelet server certificate rotation could lead to downtime due to expired certificates.",
|
||||
"RelatedUrl": "https://kubernetes.io/docs/tasks/tls/certificate-rotation/",
|
||||
"Description": "**Kubernetes controller manager** configuration includes the `RotateKubeletServerCertificate=true` feature gate for automatic rotation of **kubelet server certificates**",
|
||||
"Risk": "Without **certificate rotation**, kubelet HTTPS endpoints can use expired or long-lived certs, triggering TLS failures and operational gaps. Teams may bypass verification, enabling **MitM** and tampering. This harms **availability** and **integrity**, and extends exposure if a private key is compromised.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://kubernetes.io/docs/tasks/tls/certificate-rotation/#understanding-the-certificate-rotation-configuration"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "--feature-gates='RotateKubeletServerCertificate=true'",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/kubernetes/kubernetes-policy-index/ensure-that-the-rotatekubeletservercertificate-argument-is-set-to-true-for-controller-manager#kubernetes",
|
||||
"Other": "",
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "1. SSH to a control-plane node and open the controller manager static pod manifest:\n - /etc/kubernetes/manifests/kube-controller-manager.yaml\n2. In spec.containers[0].command, add or update this flag:\n ```\n --feature-gates=RotateKubeletServerCertificate=true\n ```\n3. Save the file; the kubelet will automatically restart the pod with the updated setting.",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Enable kubelet server certificate rotation in the Controller Manager for automated certificate management.",
|
||||
"Url": "https://kubernetes.io/docs/tasks/tls/certificate-rotation/#understanding-the-certificate-rotation-configuration"
|
||||
"Text": "Enable `RotateKubeletServerCertificate=true` on the controller manager and ensure kubelets participate in rotation.\n\nUse short-lived certs, automated renewal, and strict TLS validation to maintain **availability**, protect **integrity**, and uphold **cryptographic hygiene**. Avoid insecure fallbacks.",
|
||||
"Url": "https://hub.prowler.com/check/controllermanager_rotate_kubelet_server_cert"
|
||||
}
|
||||
},
|
||||
"Categories": [
|
||||
"encryption"
|
||||
"encryption",
|
||||
"cluster-security"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
|
||||
+16
-12
@@ -1,31 +1,35 @@
|
||||
{
|
||||
"Provider": "kubernetes",
|
||||
"CheckID": "controllermanager_service_account_credentials",
|
||||
"CheckTitle": "Ensure that the --use-service-account-credentials argument is set to true",
|
||||
"CheckTitle": "Controller Manager pod has --use-service-account-credentials=true",
|
||||
"CheckType": [],
|
||||
"ServiceName": "controllermanager",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "KubernetesControllerManager",
|
||||
"Severity": "high",
|
||||
"ResourceType": "Pod",
|
||||
"ResourceGroup": "container",
|
||||
"Description": "This check verifies that the Kubernetes Controller Manager is configured to use individual service account credentials for each controller, enhancing the security and role separation within the Kubernetes system.",
|
||||
"Risk": "Not using individual service account credentials can lead to overly broad permissions and potential security risks.",
|
||||
"RelatedUrl": "https://kubernetes.io/docs/reference/command-line-tools-reference/kube-controller-manager/",
|
||||
"Description": "Evaluates whether the **Kubernetes controller manager** uses per-controller service account credentials via `--use-service-account-credentials=true`, meaning each controller runs with its own identity rather than a shared credential.",
|
||||
"Risk": "Without per-controller credentials, one token can grant broad controller privileges. Compromise or misuse enables unauthorized state changes, data exposure, and lateral movement, while reducing audit granularity-impacting confidentiality and integrity.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://kubernetes.io/docs/reference/command-line-tools-reference/kube-controller-manager/#options"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "--use-service-account-credentials=true",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/kubernetes/kubernetes-policy-index/ensure-that-the-use-service-account-credentials-argument-is-set-to-true",
|
||||
"Other": "",
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "1. SSH to each control-plane node\n2. Edit the static Pod manifest: /etc/kubernetes/manifests/kube-controller-manager.yaml\n3. Under spec.containers[0].command, add a new item: --use-service-account-credentials=true\n4. Save the file; the kubelet will automatically restart the controller-manager",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Configure the Controller Manager to use individual service account credentials for enhanced security and role separation.",
|
||||
"Url": "https://kubernetes.io/docs/reference/command-line-tools-reference/kube-controller-manager/#options"
|
||||
"Text": "Enable `--use-service-account-credentials=true` and enforce **least privilege**: assign a dedicated service account per controller with minimal RBAC, limit token scope/lifetime, and monitor controller actions. This upholds **separation of duties** and **defense in depth**.",
|
||||
"Url": "https://hub.prowler.com/check/controllermanager_service_account_credentials"
|
||||
}
|
||||
},
|
||||
"Categories": [
|
||||
"trustboundaries"
|
||||
"cluster-security",
|
||||
"identity-access"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
|
||||
+16
-12
@@ -1,31 +1,35 @@
|
||||
{
|
||||
"Provider": "kubernetes",
|
||||
"CheckID": "controllermanager_service_account_private_key_file",
|
||||
"CheckTitle": "Ensure that the --service-account-private-key-file argument is set as appropriate",
|
||||
"CheckTitle": "Controller Manager pod has the --service-account-private-key-file argument set",
|
||||
"CheckType": [],
|
||||
"ServiceName": "controllermanager",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "KubernetesControllerManager",
|
||||
"Severity": "high",
|
||||
"ResourceType": "Pod",
|
||||
"ResourceGroup": "container",
|
||||
"Description": "This check ensures that the Kubernetes Controller Manager is configured with the --service-account-private-key-file argument set to the private key file for service accounts.",
|
||||
"Risk": "Not setting a private key file for service accounts can hinder the ability to securely rotate service account tokens.",
|
||||
"RelatedUrl": "https://kubernetes.io/docs/reference/access-authn-authz/service-accounts-admin/",
|
||||
"Description": "**Kubernetes controller manager** uses a **service account signing key** configured via `--service-account-private-key-file`.\n\nThe evaluation identifies whether this argument is present, indicating the component can sign service account tokens.",
|
||||
"Risk": "Without a configured signing key, the token controller can't mint service account tokens, breaking pod-to-API auth and controller operations (**availability**). Inability to rotate keys prolongs validity of stolen or stale tokens, weakening **integrity** and **confidentiality**.",
|
||||
"RelatedUrl": "",
|
||||
"AdditionalURLs": [
|
||||
"https://kubernetes.io/docs/reference/access-authn-authz/service-accounts-admin/#token-controller"
|
||||
],
|
||||
"Remediation": {
|
||||
"Code": {
|
||||
"CLI": "--service-account-private-key-file=/path/to/sa-key-file",
|
||||
"NativeIaC": "https://docs.prowler.com/checks/kubernetes/kubernetes-policy-index/ensure-that-the-service-account-private-key-file-argument-is-set-as-appropriate",
|
||||
"Other": "",
|
||||
"CLI": "",
|
||||
"NativeIaC": "",
|
||||
"Other": "1. SSH to the control plane node\n2. Edit /etc/kubernetes/manifests/kube-controller-manager.yaml\n3. Under containers[].command, add: - --service-account-private-key-file=/etc/kubernetes/pki/sa.key\n4. Save the file; the kubelet will restart the kube-controller-manager pod automatically",
|
||||
"Terraform": ""
|
||||
},
|
||||
"Recommendation": {
|
||||
"Text": "Configure the Controller Manager with a private key file for service accounts to maintain security and enable token rotation.",
|
||||
"Url": "https://kubernetes.io/docs/reference/access-authn-authz/service-accounts-admin/#token-controller"
|
||||
"Text": "Set a dedicated **signing key** using `--service-account-private-key-file`, or adopt an approved external signer.\n\nApply **least privilege** to key access, enforce **regular rotation** and rollover, separate **signing/verification** duties, and prefer short-lived tokens with strict **RBAC**.",
|
||||
"Url": "https://hub.prowler.com/check/controllermanager_service_account_private_key_file"
|
||||
}
|
||||
},
|
||||
"Categories": [
|
||||
"encryption"
|
||||
"cluster-security",
|
||||
"secrets"
|
||||
],
|
||||
"DependsOn": [],
|
||||
"RelatedTo": [],
|
||||
|
||||
Reference in New Issue
Block a user