ZBLOG

id: 4.2.2 text: "Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)" audit: "/bin/ps -fC $kubeletbin" audit_config: "/bin/cat $kubeletconf" tests: test_items: -...

{ “id”: “4.2.2”, “text”: “Ensure that the –authorization-mode argument is not set to AlwaysAllow (Automated)”, “audit”: “/bin/ps -fC \(kubeletbin", "audit_config": "/bin/cat \)kubeletconf”, “tests”: {

"test_items": [
  {
    "flag": "--authorization-mode",
    "path": "{.authorization.mode}",
    "compare": {
      "op": "nothave",
      "value": "AlwaysAllow"
    }
  }
]

}, “remediation”: “| If using a Kubelet config file, edit the file to set authorization: mode to Webhook. If\n| using executable arguments, edit the kubelet service file\n| $kubeletsvc on each worker node and\n| set the below parameter in KUBELET_AUTHZ_ARGS variable.\n| –authorization-mode=Webhook\n| Based on your system, restart the kubelet service. For example:\n| systemctl daemon-reload\n| systemctl restart kubelet.service”, “scored”: true }


内容由零声教学AI助手提供,问题来源于学员提问

本站部分文章来源于网络,版权归原作者所有,如有侵权请联系站长删除。
转载请注明出处:https://golang.0voice.com/?id=8956

分享:
扫描分享到社交APP
上一篇
下一篇
发表列表
游客 游客
此处应有掌声~
评论列表

还没有评论,快来说点什么吧~

联系我们

在线咨询: 点击这里给我发消息

微信号:3007537140

上班时间: 10:30-22:30

关注我们
x

注册

已经有帐号?