Benchmark: 7 Kubernetes Engine
Overview
This section covers recommendations addressing Kubernetes Engine on Alibaba Cloud.
Usage
Install the mod:
mkdir dashboardscd dashboardspowerpipe mod initpowerpipe mod install github.com/turbot/steampipe-mod-alicloud-compliance
Start the Powerpipe server:
steampipe service startpowerpipe server
Open http://localhost:9033 in your browser and select 7 Kubernetes Engine.
Run this benchmark in your terminal:
powerpipe benchmark run alicloud_compliance.benchmark.cis_v100_7
Snapshot and share results via Turbot Pipes:
powerpipe benchmark run alicloud_compliance.benchmark.cis_v100_7 --share
Controls
- 7.1 Ensure Log Service is set to 'Enabled' on Kubernetes Engine Clusters
- 7.4 Ensure Cluster Check triggered at least once per week for Kubernetes Clusters
- 7.5 Ensure Kubernetes web UI / Dashboard is not enabled
- 7.6 Ensure Basic Authentication is not enabled on Kubernetes Engine
- 7.7 Ensure Network policy is enabled on Kubernetes Engine Clusters
- 7.8 Ensure ENI multiple IP mode support for Kubernetes Cluster
- 7.9 Ensure Kubernetes Cluster is created with Private cluster enabled