For AI agents: A markdown version of this page is available at https://docs.datadoghq.com/security/default_rules/def-00k-gqk.md. A documentation index is available at /llms.txt.

RBAC should be enabled for the Kubernetes API server

Description

Role Based Access Control (RBAC) should be enabled. RBAC allows fine-grained control over the operations that different entities can perform on different objects in the cluster.

Remediation

Edit the API server pod specification file /etc/kubernetes/manifests/kube-apiserver.yaml on the master node, and set the --authorization-mode parameter to a value that includes RBAC. For example, --authorization-mode=Node,RBAC.