ack-cluster-ram-authenticator-enabled

Updated at:

Evaluates whether ack-ram-authenticator is installed in each Container Service for Kubernetes (ACK) cluster for Resource Access Management (RAM) authentication.

Scenario

ack-ram-authenticator authenticates requests to the API server of an ACK managed cluster through webhooks and RAM. In single sign-on (SSO) scenarios, it also authenticates API server requests from users who assume the same role.

Risk level

Default risk level: medium.

You can change the risk level when you apply this rule.

Compliance evaluation logic

An ACK cluster is compliant if ack-ram-authenticator is installed.

Rule details

Item

Description

Rule name

ack-cluster-ram-authenticator-enabled

Rule ID

ack-cluster-ram-authenticator-enabled

Tag

ACK and Cluster

Automatic remediation

Not supported

Trigger type

Periodic execution

Evaluation frequency

Every 24 hours

Supported resource type

ACS::ACK::Cluster

Input parameter

None

Non-compliance remediation

Install ack-ram-authenticator in all ACK clusters. Use ack-ram-authenticator to help the API server in an ACK managed cluster complete webhook authentication.