Checks whether cluster auditing is enabled for each Container Service for Kubernetes (ACK) cluster.
Scenario
ACK API server audit logs help administrators track user operations. Cluster auditing is essential for security and O&M.
Risk level
Default risk level: high.
You can change the risk level when you apply this rule.
Compliance evaluation logic
Compliant if cluster auditing is enabled for each ACK cluster.
Rule details
|
Item |
Description |
|
Rule name |
ack-cluster-api-server-audit-log-enabled |
|
Rule ID |
|
|
Tag |
ACK and Cluster |
|
Automatic remediation |
Not supported |
|
Trigger type |
Periodic execution |
|
Evaluation frequency |
Every 24 hours |
|
Supported resource type |
ACS::ACK::Cluster |
|
Input parameter |
None |
Non-compliance remediation
Enable cluster auditing for all ACK clusters. Work with the cluster auditing feature.