Skip to main content

Allowlist CSP-Provided Cluster Add-ons and Extensions

CCC.K8S.CN08 · Orchestration

Restrict enabled CSP-provided cluster add-ons, extensions, and managed features to an organization-controlled allowlist.

Related Capabilities

IDTitleDescription
CCC.K8S.CP14Managed Cluster ExtensionsThe service can manage the installation and lifecycle of supported extensions for networking, storage, policy, observability, and workload management.
CCC.K8S.CP18Admission Policy EnforcementThe service may be configured with policies, admission controllers, and webhooks that validate, mutate, or reject Kubernetes API requests before persistence.

Related Threats

IDTitleDescription
CCC.K8S.TH08Cluster Extensions Execute Untrusted CodeAn operator, controller, admission webhook, or managed extension installed without verified provenance and constrained permissions may execute untrusted code with cluster-level access. The extension can intercept sensitive data, rewrite cluster state, or interrupt workloads across its granted scope.

Assessment Requirements

IDTextApplicability
CCC.K8S.CN08.AR01When a CSP-provided cluster add-on, extension, or managed feature is enabled, it MUST be included in an organization-controlled allowlist.tlp-clear, tlp-green, tlp-amber, tlp-red

Guideline Mappings

FrameworkIDRemarks
NIST_800_53SI-7Software, Firmware, and Information Integrity
NIST_800_53SR-3Supply Chain Controls and Processes