The Kubernetes API server should only allow explicitly authorized requests

Set up the kubernetes integration.

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。

Description

The API server should not be configured to allow all requests. This mode should not be used on any production cluster.

Remediation

Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml on the master node, and set the --authorization-mode parameter to values other than AlwaysAllow. For example, --authorization-mode=RBAC,Node.