Skip to main content

More Info:

Ensure that the certificate authorities file ownership is set to root:root.

Risk Level

Low

Address

Security

Compliance Standards

  • APRA CPS 234 (Australia)
  • BSI C5 (Germany)
  • Brazil LGPD
  • CCPA / CPRA (California)
  • CIS Critical Security Controls v8
  • CIS EKS
  • CMMC 2.0
  • CSA Cloud Controls Matrix v4
  • DPDPA
  • Digital Operational Resilience Act (EU)
  • Essential 8
  • ISO/IEC 27017
  • ISO/IEC 27018
  • ISO/IEC 27701
  • KSA PDPL
  • MAS Technology Risk Management (Singapore)
  • MITRE ATT&CK (Cloud)
  • NIS2 Directive
  • NIST SP 800-171
  • NYDFS 23 NYCRR 500
  • SWIFT Customer Security Controls Framework
  • Sarbanes-Oxley IT General Controls
  • UK NCSC Cyber Assessment Framework

Triage and Remediation

Remediation

Manual Steps

  1. On every worker node, check the current ownership of the kubelet configuration file:
  2. On every worker node, set the ownership of the kubelet configuration file to root:root:
  3. On every worker node, re-verify the ownership matches root:root:
kubectl cannot modify ownership or permissions of host-level files such as /var/lib/kubelet/config.yaml; this must be fixed directly on every worker node via the operating system. Refer to the Manual Steps section for the exact commands to run over SSH on each node.

Additional Reading: