Skip to main content

More Info:

The kubelet —authorization-mode argument must not be set to AlwaysAllow. AlwaysAllow authorizes every request to the kubelet, bypassing access controls on the node.

Risk Level

Critical

Address

Security

Compliance Standards

  • CIS OKE

Triage and Remediation

Remediation

Using Console

Refer to the remediation guidance for this control. Detailed console, CLI and Python steps are being generated.