For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/def-000-yd0.md. A documentation index is available at /llms.txt.

AKS Kubelet configuration file ownership should be assigned to root

Description

Ensure that the file ownership of the kubelet’s kubeconfig file is set to root:root. You should set its file ownership to maintain integrity.

Remediation

Run the following command to fix the kubelet configuration file’s ownership:

chown root:root /var/lib/kubelet/kubeconfig

Note: The path above is the default location in AKS.