> ## Documentation Index
> Fetch the complete documentation index at: https://cloudanix.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Controller Manager Kubeconfig File Ownership Should Be root:root

### More Info:

Verifies that the controller-manager.conf kubeconfig file is owned by root:root so only privileged users can read its client credentials.

### Risk Level

Medium

### Address

Security

### Compliance Standards

* CIS Kubernetes

### Triage and Remediation

<Tabs>
  <Tab title="Remediation">
    ### Remediation

    <AccordionGroup>
      <Accordion title="Manual Steps" defaultOpen="true">
        1. On every control plane node, confirm the file exists and view its current ownership:
           ```bash theme={null}
           ls -l /etc/kubernetes/controller-manager.conf
           ```

        2. On every control plane node, set the ownership of the kubeconfig file to root:root:
           ```bash theme={null}
           chown root:root /etc/kubernetes/controller-manager.conf
           ```

        3. (Optional, but recommended) On every control plane node, restrict the permissions so only root can read/write:
           ```bash theme={null}
           chmod 600 /etc/kubernetes/controller-manager.conf
           ```

        4. On every control plane node, verify the ownership is now root:root:
           ```bash theme={null}
           stat -c %U:%G /etc/kubernetes/controller-manager.conf
           ```
      </Accordion>

      <Accordion title="Using kubectl">
        kubectl cannot modify host-level file ownership for `/etc/kubernetes/controller-manager.conf` on control plane nodes. This must be fixed directly on each control plane node’s filesystem; see the Manual Steps section for the exact commands to run over SSH.
      </Accordion>

      <Accordion title="Automation">
        ```bash theme={null}
        #!/usr/bin/env bash
        #
        # Fix ownership of /etc/kubernetes/controller-manager.conf to root:root
        # Scope: run on every control plane node
        # Idempotent and safe to re-run

        set -euo pipefail

        TARGET_FILE="/etc/kubernetes/controller-manager.conf"
        REQUIRED_OWNER="root"
        REQUIRED_GROUP="root"

        echo "=== Controller Manager kubeconfig ownership remediation ==="

        if [[ ! -e "$TARGET_FILE" ]]; then
          echo "File not found: $TARGET_FILE"
          echo "Nothing to change on this node."
          exit 0
        fi

        # Get current ownership
        CURRENT_OWNER="$(stat -c %U "$TARGET_FILE")"
        CURRENT_GROUP="$(stat -c %G "$TARGET_FILE")"

        echo "Current ownership of $TARGET_FILE: ${CURRENT_OWNER}:${CURRENT_GROUP}"

        # Apply fix only if needed
        if [[ "$CURRENT_OWNER" != "$REQUIRED_OWNER" || "$CURRENT_GROUP" != "$REQUIRED_GROUP" ]]; then
          echo "Updating ownership to ${REQUIRED_OWNER}:${REQUIRED_GROUP} ..."
          chown "${REQUIRED_OWNER}:${REQUIRED_GROUP}" "$TARGET_FILE"
        else
          echo "Ownership already set to ${REQUIRED_OWNER}:${REQUIRED_GROUP}; no change needed."
        fi

        # Verification (adapted from audit command)
        echo "Verifying ownership..."
        RESULT="$(stat -c %U:%G "$TARGET_FILE")"
        echo "stat -c %U:%G $TARGET_FILE => $RESULT"

        if [[ "$RESULT" != "${REQUIRED_OWNER}:${REQUIRED_GROUP}" ]]; then
          echo "ERROR: Failed to set ownership to ${REQUIRED_OWNER}:${REQUIRED_GROUP} on $TARGET_FILE" >&2
          exit 1
        fi

        echo "Success: $TARGET_FILE ownership is correctly set to ${REQUIRED_OWNER}:${REQUIRED_GROUP}."
        ```

        Usage:

        * Copy this script to a file, for example `/usr/local/sbin/fix-controller-manager-kubeconfig-ownership.sh`.
        * Make it executable:

        ```bash theme={null}
        chmod 700 /usr/local/sbin/fix-controller-manager-kubeconfig-ownership-ownership.sh
        ```

        * Run on every control plane node (as root):

        ```bash theme={null}
        /usr/local/sbin/fix-controller-manager-kubeconfig-ownership-ownership.sh
        ```
      </Accordion>
    </AccordionGroup>
  </Tab>
</Tabs>
