Checks Performed
- Apply Security Context To Your Pods And Containers
- Consider External Secret Storage
- Consider Fargate Running Untrusted Workloads
- Create Administrative Boundaries Between Resources Using Namespaces
- Create Administrative Boundaries Between Resources Using Namespaces
- Enable Audit Logs
- Encrypt Traffic Https Load Balancers With Tls Certificates
- Encrypt Traffic To HTTPS Load Balancers With TLS Certificates
- Ensure Anonymous Auth Argument Is Disabled
- Ensure Audit Logs Are Collected And Managed
- Ensure Authorization Mode Argument Is Not Set Always Allow
- Ensure Client Ca File Argument Is Set Appropriate
- Ensure Cluster Admin Role Is Only Used Where Required
- Ensure Clusters Are Created With Private Endpoint Enabled And Public Access Disabled
- Ensure Clusters Are Created With Private Endpoint Enabled And Public Access Disabled
- Ensure Clusters Are Created With Private Nodes
- Ensure Clusters Are Created With Private Nodes
- Ensure CNI Plugin Supports Network Policies
- Ensure Default Service Accounts Not Actively Used.
- Ensure Event Record Qps Argument Is Set To 0 Level Which Ensures Appropriate Event Capture
- Ensure Hostname Override Argument Is Not Set
- Ensure Image Vulnerability Scanning Using Amazon Ecr Image Scanning Or Third Party Provider
- Ensure Image Vulnerability Scanning Using Amazon ECR Or Third Party Provider
- Ensure Kubeconfig File Permissions Are Set Restrictive
- Ensure Kubelet Configuration File Ownership Is Set Root
- Ensure Kubelet Configuration File Ownership Is Set To root:root
- Ensure Kubelet Configuration File Permissions Are 644 Or More Restrictive
- Ensure Kubelet Configuration File Should Have Permissions Set Restrictive
- Ensure Kubelet Kubeconfig File Ownership Is Set Root
- Ensure Kubelet Kubeconfig File Ownership Is Set To root:root
- Ensure Kubelet Kubeconfig File Permissions Are 644 Or More Restrictive
- Ensure Kubernetes Secrets Are Encrypted Using CMKs Managed In AWS KMS
- Ensure Kubernetes Secrets Are Encrypted Using Customer Master Keys Managed AWS KMS
- Ensure Latest Cni Version Is Used
- Ensure Make Iptables Util Chains Argument Is Enabled
- Ensure Network Policy Is Enabled And Set Appropriate
- Ensure Network Policy Is Enabled And Set As Appropriate
- Ensure Protect Kernel Defaults Argument Is Enabled
- Ensure Read Only Port Is Secured
- Ensure Rotate Certificates Argument Is Not Set Disabled
- Ensure Rotate Kubelet Server Certificate Argument Is Enabled
- Ensure Service Account Tokens Are Only Mounted Where Necessary
- Ensure Streaming Connection Idle Timeout Argument Is Not Set 0
- Ensure That A Client CA File Is Configured
- Ensure That All Namespaces Have Network Policies Defined
- Ensure That All Namespaces Have Network Policies Defined
- Ensure That Anonymous Auth Is Not Enabled
- Ensure That Default Service Accounts Are Not Actively Used
- Ensure That Service Account Tokens Are Only Mounted Where Necessary
- Ensure That The —authorization-mode Argument Is Not Set To AlwaysAllow
- Ensure That The —eventRecordQPS Argument Is Set Appropriately
- Ensure That The —make-iptables-util-chains Argument Is Set To True
- Ensure That The —read-only-port Is Disabled
- Ensure That The —rotate-certificates Argument Is Not Present Or Is Set To True
- Ensure That The —streaming-connection-idle-timeout Argument Is Not Set To 0
- Ensure That The RotateKubeletServerCertificate Argument Is Set To True
- Ensure The Cluster-Admin Role Is Only Used Where Required
- Limit Use Of The Bind, Impersonate And Escalate Permissions
- Manage Kubernetes Rbac Users With Aws Iam Authenticator For Kubernetes
- Manage Kubernetes RBAC Users With AWS IAM Authenticator Or Upgrade AWS CLI
- Minimize Access Create Pods
- Minimize Access To Create PersistentVolume Objects
- Minimize Access To Create Pods
- Minimize Access To Secrets
- Minimize Access To Secrets
- Minimize Access To The Proxy Sub-Resource Of Node Objects
- Minimize Access To The Service Account Token Creation
- Minimize Access To Webhook Configuration Objects
- Minimize Admission Containers Wishing Share Host Ipc Namespace
- Minimize Admission Containers Wishing Share Host Process Id Namespace
- Minimize Admission Containers Wishing Share The Host Network Namespace
- Minimize Admission Containers With Allow Privilege Escalation
- Minimize Admission Privileged Containers
- Minimize Admission Root Containers
- Minimize Cluster Access Read Only For Amazon Ecr
- Minimize Cluster Access To Read-Only For Amazon ECR
- Minimize Container Registries Only Those Approved
- Minimize Container Registries To Only Those Approved
- Minimize The Admission Containers With Added Capabilities
- Minimize The Admission Containers With Capabilities Assigned
- Minimize The Admission Containers With The Net Raw Capability
- Minimize The Admission Of Containers Sharing The Host IPC Namespace
- Minimize The Admission Of Containers Sharing The Host Network Namespace
- Minimize The Admission Of Containers Sharing The Host Process ID Namespace
- Minimize The Admission Of Containers With allowPrivilegeEscalation
- Minimize The Admission Of Privileged Containers
- Minimize User Access To Amazon Ecr
- Minimize User Access To Amazon ECR
- Minimize Wildcard Use In Roles And ClusterRoles
- Minimize Wildcard Use Roles And Cluster Roles
- Prefer Using Container Optimized Os When Possible
- Prefer Using Dedicated Amazon EKS Service Accounts
- Prefer Using Dedicated Amazon Eks Service Accounts
- Prefer Using Secrets As Files Over Secrets As Environment Variables
- Prefer Using Secrets Files Over Secrets Environment Variables
- Restrict Access To Control Plane Endpoint
- Restrict Access To The Control Plane Endpoint
- The Default Namespace Should Not Be Used
- The Default Namespace Should Not Be Used
- Use Cluster Access Manager API To Manage Access Controls

