C-0318 - Ensure that the --seccomp-default parameter is set to true

Prerequisites

Run Kubescape with host sensor (seehere)

Framework

CIS v1.12.0 (CIS-4.2.14)

Severity

Low

Description of the the issue

Seccomp restricts the system calls a container can make. When seccompDefault is enabled, the kubelet applies the RuntimeDefault seccomp profile to every workload that doesn't set its own profile, instead of running it unconfined. Without it, a workload that omits a seccomp profile has the full system call surface available, which widens what an attacker can reach after a container compromise.

Related Resources

Kubelet (node configuration)

What does this control test

The control checks each node's kubelet configuration and verifies that the seccomp default parameter is set, either through the --seccomp-default command-line argument or the seccompDefault setting in the kubelet config file. CIS marks 4.2.14 as Manual and unscored, and its audit tests only that the parameter is set, not its value. This control follows the same approach.

Remediation

Set the parameter in one of the following ways:

  • Add --seccomp-default=true to the kubelet command-line arguments.
  • Set seccompDefault: true in the kubelet config file.

Then restart the kubelet:

systemctl daemon-reload systemctl restart kubelet.service

Impact Statement

Workloads that don't declare a seccomp profile will run under RuntimeDefault. A workload that relies on a system call blocked by RuntimeDefault will fail until it declares its own profile.

Default Value

--seccomp-default is not set, which is equivalent to false.

Example
No example


Did this page help you?