CIS Benchmark

IDDescriptionCode
CIS.1.2.1Ensure that the --anonymous-auth argument is set to falseLink
CIS.1.2.10Ensure that the admission control plugin EventRateLimit is setLink
CIS.1.2.11Ensure that the admission control plugin AlwaysAdmit is not setLink
CIS.1.2.12Ensure that the admission control plugin AlwaysPullImages is setLink
CIS.1.2.13Ensure that the admission control plugin SecurityContextDeny is set if PodSecurityPolicy is not usedLink
CIS.1.2.14Ensure that the admission control plugin ServiceAccount is setLink
CIS.1.2.15Ensure that the admission control plugin NamespaceLifecycle is setLink
CIS.1.2.16Ensure that the admission control plugin PodSecurityPolicy is setLink
CIS.1.2.17Ensure that the admission control plugin NodeRestriction is setLink
CIS.1.4.1Ensure that the --profiling argument is set to falseLink
CIS.2.1Ensure that the --cert-file and --key-file arguments are set as appropriateLink
CIS.2.2Ensure that the --client-cert-auth argument is set to trueLink
CIS.2.3Ensure that the --auto-tls argument is not set to trueLink
CIS.2.4Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriateLink
CIS.2.5Ensure that the --peer-client-cert-auth argument is set to trueLink
CIS.2.6Ensure that the --peer-auto-tls argument is not set to trueLink
CIS.2.7Ensure that a unique Certificate Authority is used for etcdLink
CIS.5.1.1Ensure that the cluster-admin role is only used where requiredLink
CIS.5.1.3Minimize wildcard use in Roles and ClusterRolesLink
CIS.5.5.1Configure Image Provenance using ImagePolicyWebhook admission controllerLink