More Info:
Ensure that the certificate authorities file ownership is set to root:root.Risk Level
LowAddress
SecurityCompliance Standards
- APRA CPS 234 (Australia)
- BSI C5 (Germany)
- Brazil LGPD
- CCPA / CPRA (California)
- CIS Critical Security Controls v8
- CIS EKS
- CMMC 2.0
- CSA Cloud Controls Matrix v4
- DPDPA
- Digital Operational Resilience Act (EU)
- Essential 8
- ISO/IEC 27017
- ISO/IEC 27018
- ISO/IEC 27701
- KSA PDPL
- MAS Technology Risk Management (Singapore)
- MITRE ATT&CK (Cloud)
- NIS2 Directive
- NIST SP 800-171
- NYDFS 23 NYCRR 500
- SWIFT Customer Security Controls Framework
- Sarbanes-Oxley IT General Controls
- UK NCSC Cyber Assessment Framework
Triage and Remediation
- Remediation
Remediation
Manual Steps
Manual Steps
-
On every worker node, check the current ownership of the kubelet configuration file:
-
On every worker node, set the ownership of the kubelet configuration file to root:root:
-
On every worker node, re-verify the ownership matches root:root:
Using kubectl
Using kubectl
kubectl cannot modify ownership or permissions of host-level files such as
/var/lib/kubelet/config.yaml; this must be fixed directly on every worker node via the operating system. Refer to the Manual Steps section for the exact commands to run over SSH on each node.Automation
Automation

