Container Service for Kubernetes (ACK) provides API Server audit logs that record all requests to the Kubernetes API and their outcomes. Use these logs to trace cluster operations, troubleshoot failures, and identify who performed what action on which resource and when. You can also use these logs to simplify security operations and maintenance (O&M).
Prerequisites
You have connected Container Service for Kubernetes (ACK) to Cloud Monitor.
Procedure
Log on to the Cloud Monitor 2.0 console, and select a workspace. In the left navigation pane, choose .
-
In the navigation pane of CloudLens for Container, choose .
-
On the page that appears, view the cluster audit charts on the audit overview tab.
-
At the top of the audit overview page, select dimensions such as namespace, RAM user, and status code to view the corresponding data charts.
-
The Cluster Audit dashboard includes the following charts.
Metric
Description
Total Number of Events
The total number of events in the cluster.
Public network access count
The number of public network access requests to the cluster.
Unauthorized Access Count
The number of unauthorized access attempts in the cluster.
Events Created
The number of resource creation events in the cluster.
Deleted Event Count
The number of resource deletion events in the cluster.
API Server Redirection Count
The number of API Server redirect responses in the cluster.
Operation distribution by RAM user
The distribution of operations performed by each RAM user.
Delete Event Distribution
The distribution of deletion events across the cluster.
Operation Trace
Detailed records of operations performed in the cluster.
Geographic Distribution of Public Access
The geographic distribution of public network access to the cluster.
Public Access List
Detailed records of public network access to the cluster.
Command Execution List
A summary of commands executed in the cluster.
Attach Execution List
Statistics on attach operations in the cluster.
Secret access
Records of Secret resource access in the cluster.
Delete Event List
A list of resource deletion events in the cluster.
Kubernetes CVE-2022-3172 Security Vulnerability
Displays potential Kubernetes CVE security risks in the cluster. Select or enter a RAM user ID for a real-time query. The report shows the Kubernetes CVE security risks for the current account. For more information about CVE details and solutions, see CVE Vulnerability Remediation.
-
After the chart data is returned, you can also click the
icon in the upper-right corner of the target area for more options. For example, you can view the chart in full screen or preview the query for the pinned area.