Checks Performed
- An Admission Policy Engine Should Enforce Workload Policy
- Apply Security Context To Your Pods And Containers
- Audit Logging Should Be Enabled And Shipped Off-Cluster
- Azure Json File Ownership Set To Root Root
- Azure Json File Permissions Set To 644 Or More Restrictive
- Consider External Secret Storage
- Container Images Should Not Use The latest Or Untagged Tag
- Containers Should Define Liveness And Readiness Probes
- Containers Should Disallow Privilege Escalation
- Containers Should Drop All Linux Capabilities
- Containers Should Not Run In Privileged Mode
- Containers Should Run As Non-Root
- Containers Should Set CPU And Memory Limits
- Containers Should Set CPU And Memory Requests
- Containers Should Use A Read-Only Root Filesystem
- Create Administrative Boundaries Between Resources Using Namespaces
- Enable Audit Logs
- Enable Image Vulnerability Scanning With Microsoft Defender
- Encrypt Traffic To HTTPS Load Balancers With TLS Certificates
- Ensure Clusters Are Created With Private Nodes
- Ensure Clusters Use Private Endpoint With Public Access Disabled
- Ensure Default Service Accounts Are Not Actively Used
- Ensure Kubernetes Secrets Are Encrypted
- Ensure Latest CNI Version Is Used
- Ensure Network Policy Is Enabled And Set Appropriately
- Ensure Service Account Tokens Are Only Mounted Where Necessary
- Ensure That All Namespaces Have Network Policies Defined
- Ensure The Cluster-Admin Role Is Only Used Where Required
- Every Non-System Namespace Should Have A Default-Deny NetworkPolicy
- Kubelet Anonymous Auth Set To False
- Kubelet Authorization Mode Not Set To AlwaysAllow
- Kubelet Client CA File Set As Appropriate
- Kubelet Event Record QPS Set For Appropriate Event Capture
- Kubelet Kubeconfig File Ownership Set To Root Root
- Kubelet Kubeconfig File Permissions Set To 644 Or More Restrictive
- Kubelet Make IPTables Util Chains Set To True
- Kubelet Read Only Port Secured
- Kubelet Rotate Certificates Not Set To False
- Kubelet RotateKubeletServerCertificate Set To True
- Kubelet Streaming Connection Idle Timeout Not Set To Zero
- Limit Use Of The Bind, Impersonate And Escalate Permissions
- Manage Kubernetes RBAC Users With Azure AD
- Minimize Access To Create Persistent Volumes
- Minimize Access To Create Pods
- Minimize Access To Secrets
- Minimize Access To The Approval Sub-Resource Of CertificateSigningRequests
- Minimize Access To The Proxy Sub-Resource Of Nodes
- Minimize Access To The Service Account Token Creation
- Minimize Access To Webhook Configuration Objects
- Minimize Cluster Access To Read-Only For Azure Container Registry
- Minimize Container Registries To Only Those Approved
- Minimize The Admission Of Containers Sharing The Host IPC Namespace
- Minimize The Admission Of Containers Sharing The Host Network Namespace
- Minimize The Admission Of Containers Sharing The Host Process ID Namespace
- Minimize The Admission Of Containers With allowPrivilegeEscalation
- Minimize The Admission Of Privileged Containers
- Minimize User Access To Azure Container Registry
- Minimize Wildcard Use In Roles And ClusterRoles
- Multi-Replica Deployments Should Have A PodDisruptionBudget
- Mutable Image Tags Should Use imagePullPolicy Always
- Namespaces Should Enforce Pod Security Admission Baseline Or Stricter
- No RoleBinding Should Grant Access To Anonymous Or Unauthenticated Users
- No ServiceAccount Should Be Bound To cluster-admin
- No Workloads Should Run In The default Namespace
- Pods Should Be Managed By A Controller
- Pods Should Not Mount HostPath Volumes
- Pods Should Not Share Host Namespaces
- Pods That Do Not Use The API Should Disable Token Automount
- pods/exec Should Not Be Granted To Broad Subjects
- Prefer Bound Projected ServiceAccount Tokens Over Secret Tokens
- Prefer Using Dedicated AKS Service Accounts
- Prefer Using Secrets As Files Over Secrets As Environment Variables
- Restrict Access To The Control Plane Endpoint
- Secrets Should Be Encrypted At Rest
- Sensitive Values Should Not Be Passed As Literal Env Vars
- Tenant Namespaces Should Have A ResourceQuota
- The Default Namespace Should Not Be Used
- Use Azure RBAC For Kubernetes Authorization

