Checks Performed
- Access Control And Container Engine For Kubernetes
- An Admission Policy Engine Should Enforce Workload Policy
- Apply Security Context To Your Pods And Containers
- Audit Logging Should Be Enabled And Shipped Off-Cluster
- Client Certificate Authentication Should Not Be Used For Users
- Consider External Secret Storage
- Container Images Should Not Use The latest Or Untagged Tag
- Containers Should Define Liveness And Readiness Probes
- Containers Should Disallow Privilege Escalation
- Containers Should Drop All Linux Capabilities
- Containers Should Not Run In Privileged Mode
- Containers Should Run As Non-Root
- Containers Should Set CPU And Memory Limits
- Containers Should Set CPU And Memory Requests
- Containers Should Use A Read-Only Root Filesystem
- Create Administrative Boundaries Between Resources Using Namespaces
- Encrypt Traffic To HTTPS Load Balancers With TLS Certificates
- Encrypting Kubernetes Secrets At Rest In Etcd
- Ensure Access To OCI Audit Service Log For OKE
- Ensure All Namespaces Have Network Policies Defined
- Ensure Clusters Are Created With Private Endpoint Enabled And Public Access Disabled
- Ensure Clusters Are Created With Private Nodes
- Ensure Default Service Accounts Are Not Actively Used
- Ensure Kubelet Kubeconfig File Ownership Is Set Root
- Ensure Latest CNI Version Is Used
- Ensure Network Policy Is Enabled And Set As Appropriate
- Ensure Service Account Tokens Are Only Mounted Where Necessary
- Every Non-System Namespace Should Have A Default-Deny NetworkPolicy
- Kubelet Anonymous Auth Argument Set To False
- Kubelet Authorization Mode Not Set To AlwaysAllow
- Kubelet Client CA File Argument Set As Appropriate
- Kubelet Configuration File Ownership Set To root:root
- Kubelet Configuration File Permissions Set To 644 Or More Restrictive
- Kubelet Event QPS Argument Set For Appropriate Event Capture
- Kubelet Kubeconfig File Ownership Set To root:root
- Kubelet Kubeconfig File Permissions Set To 644 Or More Restrictive
- Kubelet Make Iptables Util Chains Argument Set To True
- Kubelet Read Only Port Argument Set To 0
- Kubelet Rotate Certificates Argument Not Set To False
- Kubelet Rotate Server Certificates Argument Set To True
- Kubelet Streaming Connection Idle Timeout Not Set To 0
- Kubelet TLS Cert File And TLS Private Key File Arguments Set As Appropriate
- Minimize Access To Create Pods
- Minimize Access To Secrets
- Minimize Admission Of Containers Sharing The Host IPC Namespace
- Minimize Admission Of Containers Sharing The Host Network Namespace
- Minimize Admission Of Containers Sharing The Host Process ID Namespace
- Minimize Admission Of Containers With allowPrivilegeEscalation
- Minimize Cluster Access To Read-Only
- Minimize Container Registries To Only Those Approved
- Minimize The Admission Of Privileged Containers
- Minimize User Access Control To Container Engine For Kubernetes
- Minimize Wildcard Use In Roles And ClusterRoles
- Multi-Replica Deployments Should Have A PodDisruptionBudget
- Mutable Image Tags Should Use imagePullPolicy Always
- Namespaces Should Enforce Pod Security Admission Baseline Or Stricter
- No RoleBinding Should Grant Access To Anonymous Or Unauthenticated Users
- No ServiceAccount Should Be Bound To cluster-admin
- No Workloads Should Run In The default Namespace
- Oracle Cloud Security Penetration and Vulnerability Testing
- Pods Should Be Managed By A Controller
- Pods Should Not Mount HostPath Volumes
- Pods Should Not Share Host Namespaces
- Pods That Do Not Use The API Should Disable Token Automount
- pods/exec Should Not Be Granted To Broad Subjects
- Prefer Bound Projected ServiceAccount Tokens Over Secret Tokens
- Prefer Using Dedicated Service Accounts
- Prefer Using Secrets As Files Over Secrets As Environment Variables
- Restrict Access To The Control Plane Endpoint
- Restrict Use Of Cluster-Admin Role
- Secrets Should Be Encrypted At Rest
- Sensitive Values Should Not Be Passed As Literal Env Vars
- Tenant Namespaces Should Have A ResourceQuota
- The Default Namespace Should Not Be Used

