Skip to main content

More Info:

Kubernetes can audit the details of requests made to the API server. The —auditpolicy-file flag must be set for this logging to be enabled.

Risk Level

Low

Address

Security

Compliance Standards

  • CIS Kubernetes

Triage and Remediation

Remediation

Using Console

Run the following command on one of the cluster master nodes: ps -ef | grep kube-apiserver Verify that the —audit-policy-file is set. Review the contents of the file specified and ensure that it contains a valid audit policy

Additional Reading: