diff --git a/cfg/master.yaml b/cfg/master.yaml index db7a5cdd70b53ac08978e24d373a13e9cf8b931c..dd0d07adbdd884f135f4376ed1806c0b53e4bed4 100644 --- a/cfg/master.yaml +++ b/cfg/master.yaml @@ -59,16 +59,19 @@ groups: the --insecure-allow-any-token argument from the KUBE_API_ARGS parameter." scored: true - - id: 1.1.5 + - id: 1.1.5 text: "Ensure that the --kubelet-https argument is set to true (Scored)" audit: "ps -ef | grep kube-apiserver | grep -v grep" tests: test_items: + bin_flag: or - flag: "--kubelet-https" compare: op: eq value: true set: true + - flag: "--kubelet-https" + set: false remediation: "Edit the $kubeConfDir/apiserver file on the master node and remove the --kubelet-https argument from the KUBE_API_ARGS parameter." scored: true