> ## Documentation Index
> Fetch the complete documentation index at: https://cloudanix.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Ensure Controller Manager Pod Specification File Ownership Is Root

### More Info:

Ensure that the controller manager pod specification file ownership is set to root:root.

### Risk Level

Medium

### Address

Security

### Compliance Standards

* CIS Kubernetes

### Triage and Remediation

<Tabs>
  <Tab title="Remediation">
    ### Remediation

    <AccordionGroup>
      <Accordion title="Manual Steps" defaultOpen="true">
        1. On every control plane node, confirm the controller manager manifest exists and check its current ownership:
           ```bash theme={null}
           sudo ls -l /etc/kubernetes/manifests/kube-controller-manager.yaml
           sudo stat -c %U:%G /etc/kubernetes/manifests/kube-controller-manager.yaml
           ```

        2. On every control plane node, set the file owner and group to root:
           ```bash theme={null}
           sudo chown root:root /etc/kubernetes/manifests/kube-controller-manager.yaml
           ```

        3. (Optional) On every control plane node, ensure any configuration management or bootstrap scripts (if present) also set the correct ownership so it is not reverted. For example, inspect for references:
           ```bash theme={null}
           sudo grep -R "kube-controller-manager.yaml" /etc /var -n || true
           ```

        4. Be aware that editing files under `/etc/kubernetes/manifests` can trigger a restart of the corresponding static pod, but changing ownership only should not modify the pod content. Proceed during a maintenance window if your change process requires it.

        5. On every control plane node, verify the ownership is now `root:root`:
           ```bash theme={null}
           sudo stat -c %U:%G /etc/kubernetes/manifests/kube-controller-manager.yaml
           ```
           The output must be:
           ```text theme={null}
           root:root
           ```
      </Accordion>

      <Accordion title="Using kubectl">
        Kubectl cannot modify host-level file ownership for `/etc/kubernetes/manifests/kube-controller-manager.yaml`; this must be corrected directly on every control plane node via OS tools (for example, `chown`). See the Manual Steps section for the exact commands to run on the nodes.
      </Accordion>

      <Accordion title="Automation">
        ```bash theme={null}
        #!/usr/bin/env bash
        #
        # Automation: Ensure kube-controller-manager pod spec file is owned by root:root
        # Scope: Run on every control plane node
        # Usage: sudo ./fix-kcm-ownership.sh

        set -euo pipefail

        KCM_MANIFEST="/etc/kubernetes/manifests/kube-controller-manager.yaml"
        REQUIRED_OWNER="root"
        REQUIRED_GROUP="root"

        echo "=== Checking kube-controller-manager manifest ownership on this node ==="

        if [ ! -e "$KCM_MANIFEST" ]; then
          echo "INFO: $KCM_MANIFEST does not exist on this node. Nothing to do."
          exit 0
        fi

        current_owner="$(stat -c %U "$KCM_MANIFEST")"
        current_group="$(stat -c %G "$KCM_MANIFEST")"

        echo "Current ownership: $current_owner:$current_group"
        echo "Required ownership: $REQUIRED_OWNER:$REQUIRED_GROUP"

        if [ "$current_owner" = "$REQUIRED_OWNER" ] && [ "$current_group" = "$REQUIRED_GROUP" ]; then
          echo "Ownership already correct. No changes needed."
        else
          echo "Fixing ownership..."
          chown "${REQUIRED_OWNER}:${REQUIRED_GROUP}" "$KCM_MANIFEST"
        fi

        echo "=== Verifying ownership ==="
        stat -c %U:%G "$KCM_MANIFEST"

        if [ "$(stat -c %U "$KCM_MANIFEST")" = "$REQUIRED_OWNER" ] && \
           [ "$(stat -c %G "$KCM_MANIFEST")" = "$REQUIRED_GROUP" ]; then
          echo "SUCCESS: $KCM_MANIFEST is owned by ${REQUIRED_OWNER}:${REQUIRED_GROUP}"
          exit 0
        else
          echo "ERROR: Failed to enforce ownership on $KCM_MANIFEST" >&2
          exit 1
        fi
        ```
      </Accordion>
    </AccordionGroup>
  </Tab>
</Tabs>

### Additional Reading:

* [https://kubernetes.io/docs/admin/kube-controller-manager](https://kubernetes.io/docs/admin/kube-controller-manager)
