Checks Performed
- An Admission Policy Engine Should Enforce Workload Policy
- Audit Logging Should Be Enabled And Shipped Off-Cluster
- Consider External Secret Storage
- Container Images Should Not Use The latest Or Untagged Tag
- Containers Should Define Liveness And Readiness Probes
- Containers Should Disallow Privilege Escalation
- Containers Should Drop All Linux Capabilities
- Containers Should Not Run In Privileged Mode
- Containers Should Run As Non-Root
- Containers Should Set CPU And Memory Limits
- Containers Should Set CPU And Memory Requests
- Containers Should Use A Read-Only Root Filesystem
- Create Administrative Boundaries Between Resources Using Namespaces
- Enable Audit Logs
- Encrypt Traffic To HTTPS Load Balancers With TLS Certificates
- Ensure Audit Logs Are Collected And Managed
- Ensure Clusters Are Created With Private Endpoint Enabled And Public Access Disabled
- Ensure Clusters Are Created With Private Nodes
- Ensure CNI Plugin Supports Network Policies
- Ensure Image Vulnerability Scanning Using Amazon ECR Or Third Party Provider
- Ensure Kubelet Configuration File Ownership Is Set To root:root
- Ensure Kubelet Configuration File Permissions Are 644 Or More Restrictive
- Ensure Kubelet Kubeconfig File Ownership Is Set To root:root
- Ensure Kubelet Kubeconfig File Permissions Are 644 Or More Restrictive
- Ensure Kubernetes Secrets Are Encrypted Using CMKs Managed In AWS KMS
- Ensure Network Policy Is Enabled And Set As Appropriate
- Ensure That A Client CA File Is Configured
- Ensure That All Namespaces Have Network Policies Defined
- Ensure That Anonymous Auth Is Not Enabled
- Ensure That Default Service Accounts Are Not Actively Used
- Ensure That Service Account Tokens Are Only Mounted Where Necessary
- Ensure That The —authorization-mode Argument Is Not Set To AlwaysAllow
- Ensure That The —eventRecordQPS Argument Is Set Appropriately
- Ensure That The —make-iptables-util-chains Argument Is Set To True
- Ensure That The —read-only-port Is Disabled
- Ensure That The —rotate-certificates Argument Is Not Present Or Is Set To True
- Ensure That The —streaming-connection-idle-timeout Argument Is Not Set To 0
- Ensure That The RotateKubeletServerCertificate Argument Is Set To True
- Ensure The Cluster-Admin Role Is Only Used Where Required
- Every Non-System Namespace Should Have A Default-Deny NetworkPolicy
- Limit Use Of The Bind, Impersonate And Escalate Permissions
- Manage Kubernetes RBAC Users With AWS IAM Authenticator Or Upgrade AWS CLI
- Minimize Access To Create PersistentVolume Objects
- Minimize Access To Create Pods
- Minimize Access To Secrets
- Minimize Access To The Proxy Sub-Resource Of Node Objects
- Minimize Access To The Service Account Token Creation
- Minimize Access To Webhook Configuration Objects
- Minimize Cluster Access To Read-Only For Amazon ECR
- Minimize Container Registries To Only Those Approved
- Minimize The Admission Of Containers Sharing The Host IPC Namespace
- Minimize The Admission Of Containers Sharing The Host Network Namespace
- Minimize The Admission Of Containers Sharing The Host Process ID Namespace
- Minimize The Admission Of Containers With allowPrivilegeEscalation
- Minimize The Admission Of Privileged Containers
- Minimize User Access To Amazon ECR
- Minimize Wildcard Use In Roles And ClusterRoles
- Multi-Replica Deployments Should Have A PodDisruptionBudget
- Mutable Image Tags Should Use imagePullPolicy Always
- Namespaces Should Enforce Pod Security Admission Baseline Or Stricter
- No RoleBinding Should Grant Access To Anonymous Or Unauthenticated Users
- No ServiceAccount Should Be Bound To cluster-admin
- No Workloads Should Run In The default Namespace
- Pods Should Be Managed By A Controller
- Pods Should Not Mount HostPath Volumes
- Pods Should Not Share Host Namespaces
- Pods That Do Not Use The API Should Disable Token Automount
- pods/exec Should Not Be Granted To Broad Subjects
- Prefer Bound Projected ServiceAccount Tokens Over Secret Tokens
- Prefer Using Dedicated Amazon EKS Service Accounts
- Prefer Using Secrets As Files Over Secrets As Environment Variables
- Restrict Access To The Control Plane Endpoint
- Secrets Should Be Encrypted At Rest
- Sensitive Values Should Not Be Passed As Literal Env Vars
- Tenant Namespaces Should Have A ResourceQuota
- The Default Namespace Should Not Be Used
- Use Cluster Access Manager API To Manage Access Controls

