etcd client certificate authentication set to false 이 페이지는 아직 한국어로 제공되지 않습니다. 번역 작업 중입니다.
현재 번역 프로젝트에 대한 질문이나 피드백이 있으신 경우
언제든지 연락주시기 바랍니다. Id: kubernetes-etcd-client-certificate-authentication-set-to-false
Platform: Kubernetes
Severity: Medium
Category: Secret Management
Learn More Description When containers run etcd, the --client-cert-auth flag must be set to true. This enforces client certificate authentication to prevent unauthenticated access to the etcd server. The rule reports IncorrectValue when the flag is explicitly set to false, and MissingAttribute when the flag is not defined.
Compliant Code Examples apiVersion : apps/v1
kind : Deployment
metadata :
name : app-etcd-deployment
spec :
selector :
matchLabels :
app : app
replicas : 1
template :
metadata :
labels :
app : app
version : v1
spec :
serviceAccountName : database
containers :
- name : database
image : gcr.io/google_containers/etcd:v3.2.18
imagePullPolicy : IfNotPresent
command : [ "etcd" ]
args : [ "--client-cert-auth=true" ]
nodeSelector :
kubernetes.io/hostname : worker02
restartPolicy : OnFailure
Non-Compliant Code Examples apiVersion : apps/v1
kind : Deployment
metadata :
name : app-etcd-deployment
spec :
selector :
matchLabels :
app : app
replicas : 1
template :
metadata :
labels :
app : app
version : v1
spec :
serviceAccountName : database
containers :
- name : database
image : gcr.io/google_containers/etcd:v3.2.18
imagePullPolicy : IfNotPresent
command : [ "etcd" ]
args : [ "--client-cert-auth=false" ]
nodeSelector :
kubernetes.io/hostname : worker02
restartPolicy : OnFailure
apiVersion : apps/v1
kind : Deployment
metadata :
name : app-etcd-deployment
spec :
selector :
matchLabels :
app : app
replicas : 1
template :
metadata :
labels :
app : app
version : v1
spec :
serviceAccountName : database
containers :
- name : database
image : gcr.io/google_containers/etcd:v3.2.18
imagePullPolicy : IfNotPresent
command : [ "etcd" ]
args : []
nodeSelector :
kubernetes.io/hostname : worker02
restartPolicy : OnFailure