Merge pull request #6616 from liggitt/update-securing
Update securing recommendations
This commit is contained in:
@@ -1,6 +1,9 @@
|
|||||||
---
|
---
|
||||||
approvers:
|
approvers:
|
||||||
- smarterclayton
|
- smarterclayton
|
||||||
|
- liggitt
|
||||||
|
- ericchiang
|
||||||
|
- destijl
|
||||||
title: Securing a Cluster
|
title: Securing a Cluster
|
||||||
---
|
---
|
||||||
|
|
||||||
@@ -68,6 +71,15 @@ to prevent accidental escalation. You can make roles specific to your use case i
|
|||||||
|
|
||||||
Consult the [authorization reference section](/docs/admin/authorization/) for more information.
|
Consult the [authorization reference section](/docs/admin/authorization/) for more information.
|
||||||
|
|
||||||
|
## Controlling access to the Kubelet
|
||||||
|
|
||||||
|
Kubelets expose HTTPS endpoints which give access to data of varying sensitivity, and allow performing operations with varying levels of power on the node and within containers.
|
||||||
|
|
||||||
|
By default, Kubelets allow full access to those endpoints.
|
||||||
|
|
||||||
|
To secure access to those endpoints, enable Kubelet authentication and authorization.
|
||||||
|
|
||||||
|
Consult the [Kubelet authentication/authorization reference](/docs/admin/kubelet-authentication-authorization) for more information.
|
||||||
|
|
||||||
## Controlling the capabilities of a workload or user at runtime
|
## Controlling the capabilities of a workload or user at runtime
|
||||||
|
|
||||||
@@ -151,7 +163,7 @@ access to a subset of the keyspace is strongly recommended.
|
|||||||
|
|
||||||
### Enable audit logging
|
### Enable audit logging
|
||||||
|
|
||||||
The [audit logger](/docs/tasks/debug-application-cluster/audit/) is an alpha feature that records actions taken by the
|
The [audit logger](/docs/tasks/debug-application-cluster/audit/) is a beta feature that records actions taken by the
|
||||||
API for later analysis in the event of a compromise. It is recommended to enable audit logging
|
API for later analysis in the event of a compromise. It is recommended to enable audit logging
|
||||||
and archive the audit file on a secure server.
|
and archive the audit file on a secure server.
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user