C-0318 - Ensure that the --seccomp-default parameter is set to true
Prerequisites
Run Kubescape with host sensor (seehere)
Framework
CIS v1.12.0 (CIS-4.2.14)
Severity
Low
Description of the the issue
Seccomp restricts the system calls a container can make. When seccompDefault is enabled, the kubelet applies the RuntimeDefault seccomp profile to every workload that doesn't set its own profile, instead of running it unconfined. Without it, a workload that omits a seccomp profile has the full system call surface available, which widens what an attacker can reach after a container compromise.
Related Resources
Kubelet (node configuration)
What does this control test
The control checks each node's kubelet configuration and verifies that the seccomp default parameter is set, either through the --seccomp-default command-line argument or the seccompDefault setting in the kubelet config file. CIS marks 4.2.14 as Manual and unscored, and its audit tests only that the parameter is set, not its value. This control follows the same approach.
Remediation
Set the parameter in one of the following ways:
- Add --seccomp-default=true to the kubelet command-line arguments.
- Set seccompDefault: true in the kubelet config file.
Then restart the kubelet:
systemctl daemon-reload systemctl restart kubelet.service
Impact Statement
Workloads that don't declare a seccomp profile will run under RuntimeDefault. A workload that relies on a system call blocked by RuntimeDefault will fail until it declares its own profile.
Default Value
--seccomp-default is not set, which is equivalent to false.
Example
No example
Updated about 1 hour ago
