Skip to main content

Capabilities

Version:
IDTitleDescriptionThreat Mappings
CCC.K8S.CP01Managed Kubernetes Control PlaneThe service supplies a Kubernetes-conformant control plane whose foundational components, health, and availability are automatically maintained by the provider.1
CCC.K8S.CP02Managed Worker PoolsThe service can organize worker nodes into managed pools that provide Kubernetes with compute capacity for scheduling and running containerized workloads.5
CCC.K8S.CP03Abstracted Worker InfrastructureThe service may be configured to abstract worker infrastructure so that provisioning, scaling, patching, and replacement occur without exposing individual nodes to the user.4
CCC.K8S.CP04OCI Container Image ExecutionThe service always accepts OCI-compatible image references and executes their containerized workloads through a Kubernetes-compatible runtime.1
CCC.K8S.CP05Container Registry IntegrationThe service can authenticate to private or public OCI-compatible registries and retrieve workload images with user-configured identities and credentials.1
CCC.K8S.CP06Declarative Workload OrchestrationThe service automatically reconciles Kubernetes workload resources toward their user-declared state by scheduling, restarting, and replacing containers as needed.1
CCC.K8S.CP07Cluster Network IntegrationThe service can attach cluster, node, pod, and service connectivity to a user-configured cloud virtual network.1
CCC.K8S.CP08Workload Traffic RoutingThe service can expose and route internal or external traffic to Kubernetes workloads through services, load balancers, ingress controllers, and gateway components.1
CCC.K8S.CP09Workload Network PolicyThe service may be configured with Kubernetes network policies that enforce ingress and egress boundaries between workloads and external systems.1
CCC.K8S.CP10Cloud Identity IntegrationThe service can authenticate cloud identities and authorize their access to cluster resources through Kubernetes and provider-native access controls.3
CCC.K8S.CP11Workload Identity FederationThe service may be configured to exchange Kubernetes service-account identity for short-lived cloud credentials without placing long-lived credentials in workloads.2
CCC.K8S.CP12Secrets Service IntegrationThe service can present secrets, keys, and certificates from a cloud secrets service to authorized Kubernetes workloads without embedding them in workload definitions.2
CCC.K8S.CP13Kubernetes Storage ProvisioningThe service can dynamically provision ephemeral and persistent workload storage through Kubernetes container storage interface integrations.1
CCC.K8S.CP14Managed Cluster ExtensionsThe service can manage the installation and lifecycle of supported extensions for networking, storage, policy, observability, and workload management.2
CCC.K8S.CP15Cluster Version ManagementThe service may be configured with upgrade channels and maintenance settings that keep control-plane and worker components within provider-defined compatibility and support periods.1
CCC.K8S.CP16Kubernetes Audit LoggingThe service may be configured to emit Kubernetes API audit and control-plane records to a cloud logging destination for monitoring and investigation.1
CCC.K8S.CP17Cluster Monitoring IntegrationThe service can send cluster, node, workload, and network activity telemetry to cloud-native or Kubernetes-compatible monitoring components.1
CCC.K8S.CP18Admission Policy EnforcementThe service may be configured with policies, admission controllers, and webhooks that validate, mutate, or reject Kubernetes API requests before persistence.3
CCC.K8S.CP19Workload Isolation ControlsThe service can separate workloads with security contexts, namespace boundaries, scheduling constraints, and runtime isolation settings.2
CCC.K8S.CP20Hardware Accelerator SupportThe service may be configured with worker pools equipped with supported hardware accelerators, enabling Kubernetes to schedule workloads that request those devices.0
CCC.K8S.CP21Cluster Infrastructure IdentityThe service may be configured with distinct cloud identities for control-plane, worker-node, and supporting components so their access to cloud resources can be independently authorized.1
CCC.K8S.CP22Worker Node Integrity ProtectionThe service may be configured with trusted worker-node images and platform mechanisms that verify node boot integrity before workloads are executed.1

Imports

IDRemarks
CCC.Core.CP01Encryption in Transit Enabled by Default
CCC.Core.CP02Encryption at Rest Enabled by Default
CCC.Core.CP06Access Control
CCC.Core.CP07Event Publication
CCC.Core.CP14API Access
CCC.Core.CP17Alerting
CCC.Core.CP19Child Resource Scaling
CCC.Core.CP20Resource Tagging
CCC.Core.CP22Location Lock-In
CCC.Core.CP23Network Access Rules
CCC.Core.CP24Core Processing Units
CCC.Core.CP25Random Access Memory Allocation
CCC.Core.CP26Persistent Storage
CCC.Core.CP27Configurable Network Ports
CCC.Core.CP28Command-line Interface
CCC.Core.CP29Active Ingestion
CCC.Core.CP30Passive Ingestion