Skip to main content

More Info:

The —client-cert-auth argument must be set to true so etcd requires valid client certificates for all client connections. If disabled, any client that can reach etcd can read or modify all cluster state and secrets.

Risk Level

Critical

Address

Security

Compliance Standards

  • CIS Kubernetes

Triage and Remediation

Remediation

Using Console

Refer to the remediation guidance for this control. Detailed console, CLI and Python steps are being generated.