ack-cluster-ram-authenticator-enabled
Evaluates whether ack-ram-authenticator is installed in each Container Service for Kubernetes (ACK) cluster for Resource Access Management (RAM) authentication.
Scenario
ack-ram-authenticator authenticates requests to the API server of an ACK managed cluster through webhooks and RAM. In single sign-on (SSO) scenarios, it also authenticates API server requests from users who assume the same role.
Risk level
Default risk level: medium.
You can change the risk level when you apply this rule.
Compliance evaluation logic
An ACK cluster is compliant if ack-ram-authenticator is installed.
Rule details
|
Item |
Description |
|
Rule name |
ack-cluster-ram-authenticator-enabled |
|
Rule ID |
|
|
Tag |
ACK and Cluster |
|
Automatic remediation |
Not supported |
|
Trigger type |
Periodic execution |
|
Evaluation frequency |
Every 24 hours |
|
Supported resource type |
ACS::ACK::Cluster |
|
Input parameter |
None |
Non-compliance remediation
Install ack-ram-authenticator in all ACK clusters. Use ack-ram-authenticator to help the API server in an ACK managed cluster complete webhook authentication.