SRG-APP-000342-CTR-000775 Controls

STIG IDVersionTitleProduct
CNTR-K8-002000V2R4The Kubernetes API server must have the ValidatingAdmissionWebhook enabled.
CNTR-K8-002010V2R4Kubernetes must have a pod security policy set.
CNTR-K8-002011V2R4Kubernetes must have a Pod Security Admission control file configured.
CNTR-K8-002001V2R4Kubernetes must enable PodSecurity admission controller on static pods and Kubelets.
CNTR-OS-000660V1R1Container images instantiated by OpenShift must execute using least privileges.