Cluster Audit

更新时间:
复制 MD 格式

Container Service for Kubernetes (ACK) provides API Server audit logs that record all requests to the Kubernetes API and their outcomes. Use these logs to trace cluster operations, troubleshoot failures, and identify who performed what action on which resource and when. You can also use these logs to simplify security operations and maintenance (O&M).

Prerequisites

You have connected Container Service for Kubernetes (ACK) to Cloud Monitor.

Procedure

  1. Log on to the Cloud Monitor 2.0 console, and select a workspace. In the left navigation pane, choose Application Center > CloudLens > CloudLens for Container.

  2. In the navigation pane of CloudLens for Container, choose CloudLens > Cluster Audit.

  3. On the page that appears, view the cluster audit charts on the audit overview tab.

  4. At the top of the audit overview page, select dimensions such as namespace, RAM user, and status code to view the corresponding data charts.

  5. The Cluster Audit dashboard includes the following charts.

    Metric

    Description

    Total Number of Events

    The total number of events in the cluster.

    Public network access count

    The number of public network access requests to the cluster.

    Unauthorized Access Count

    The number of unauthorized access attempts in the cluster.

    Events Created

    The number of resource creation events in the cluster.

    Deleted Event Count

    The number of resource deletion events in the cluster.

    API Server Redirection Count

    The number of API Server redirect responses in the cluster.

    Operation distribution by RAM user

    The distribution of operations performed by each RAM user.

    Delete Event Distribution

    The distribution of deletion events across the cluster.

    Operation Trace

    Detailed records of operations performed in the cluster.

    Geographic Distribution of Public Access

    The geographic distribution of public network access to the cluster.

    Public Access List

    Detailed records of public network access to the cluster.

    Command Execution List

    A summary of commands executed in the cluster.

    Attach Execution List

    Statistics on attach operations in the cluster.

    Secret access

    Records of Secret resource access in the cluster.

    Delete Event List

    A list of resource deletion events in the cluster.

    Kubernetes CVE-2022-3172 Security Vulnerability

    Displays potential Kubernetes CVE security risks in the cluster. Select or enter a RAM user ID for a real-time query. The report shows the Kubernetes CVE security risks for the current account. For more information about CVE details and solutions, see CVE Vulnerability Remediation.

  6. After the chart data is returned, you can also click the image.png icon in the upper-right corner of the target area for more options. For example, you can view the chart in full screen or preview the query for the pinned area.