Kubelet should only allow explicitly authorized requests

Set up the kubernetes integration.

Description

Explicit authorization should be enabled. Kubelets, by default, allow all authenticated requests (even anonymous ones) without needing explicit authorization checks from the API server.

Remediation

  1. If using a Kubelet config file, edit the file to set authorization: Webhook.
  2. If using executable arguments, edit the kubelet service file /etc/systemd/system/kubelet.service.d/10-kubeadm.conf on each worker node and set the below parameter in the KUBELET_AUTHZ_ARGS variable.
--authorization-mode=Webhook
  1. Restart the kubelet service.