Checks whether Secret encryption is configured for each Container Service for Kubernetes (ACK) Pro cluster. This rule does not apply to clusters that are not ACK Pro clusters.
Scenario
In ACK Pro clusters, you can encrypt Kubernetes Secrets by using keys created in Key Management Service (KMS). This ensures data security.
Risk level
Default risk level: medium.
You can change the risk level based on your business requirements when you apply this rule.
Compliance evaluation logic
Compliant if Secret encryption is configured for each ACK Pro cluster. Not applicable to non-ACK Pro clusters.
Rule details
|
Item |
Description |
|
Rule name |
ack-cluster-encryption-enabled |
|
Rule ID |
|
|
Tag |
ACK and Cluster |
|
Automatic remediation |
Not supported |
|
Trigger type |
Configuration change |
|
Supported resource type |
ACS::ACK::Cluster |
|
Input parameter |
None |
Non-compliance remediation
Configure Secret encryption for all ACK Pro clusters. For more information, see Use KMS to encrypt Kubernetes Secrets.