Workload misconfigurations

Kubernetes node’s kubelet’s rotateCertificates is set to false

Risk Level

Informational (4)

  • N/A

Compliance Frameworks


The kubelet reads various parameters, including security settings, from a config file. The --rotate-certificates setting causes the kubelet to rotate its client certificates by creating new CSRs as its existing credentials expire. This automated periodic rotation ensures that the there is no downtime due to expired certificates and thus addressing availability in the CIA security triad. Orca has detected that the rotateertificate flag is set to false on {K8sNode.Vm}.
  • Recommended Mitigation

    Set {K8sNode}'s Kubelet's rotateCertificates to true. This recommendation only applies if you let kubelets get their certificates from the API server.