Control-plane, worker, runtime, or extension versions outside their supported lifecycles may retain known vulnerabilities and compatibility defects. Exposed components can then be exploited or may fail during service changes, leading to data exposure, loss of cluster-state integrity, or workload interruption.
Unsupported Cluster Components Remain in Use
CCC.K8S.TH09
Related Capabilities
| ID | Title | Description |
|---|---|---|
| CCC.K8S.CP02 | Managed Worker Pools | The service can organize worker nodes into managed pools that provide Kubernetes with compute capacity for scheduling and running containerized workloads. |
| CCC.K8S.CP03 | Abstracted Worker Infrastructure | The service may be configured to abstract worker infrastructure so that provisioning, scaling, patching, and replacement occur without exposing individual nodes to the user. |
| CCC.K8S.CP15 | Cluster Version Management | The service may be configured with upgrade channels and maintenance settings that keep control-plane and worker components within provider-defined compatibility and support periods. |
Related Controls
| ID | Title | Description |
|---|---|---|
| CCC.K8S.CN09 | Maintain Supported Cluster Components | Keep control-plane, worker, runtime, and extension components within supported and vulnerability-managed release lifecycles. |
| CCC.K8S.CN18 | Protect Worker Node Integrity | Prevent untrusted or altered worker-node software from operating beneath Kubernetes workloads. |