Skip to main content

Worker Node Integrity Is Not Verified

CCC.K8S.TH18

Worker nodes created from untrusted or altered images, or started without boot integrity verification, may execute modified software beneath the container runtime. Modified node components can observe workload data and credentials or alter workload execution. Workload confidentiality and integrity may be lost, and node or cluster availability may be reduced.

Related Capabilities

IDTitleDescription
CCC.K8S.CP02Managed Worker PoolsThe service can organize worker nodes into managed pools that provide Kubernetes with compute capacity for scheduling and running containerized workloads.
CCC.K8S.CP03Abstracted Worker InfrastructureThe service may be configured to abstract worker infrastructure so that provisioning, scaling, patching, and replacement occur without exposing individual nodes to the user.
CCC.K8S.CP22Worker Node Integrity ProtectionThe service may be configured with trusted worker-node images and platform mechanisms that verify node boot integrity before workloads are executed.

Related Controls

IDTitleDescription
CCC.K8S.CN18Protect Worker Node IntegrityPrevent untrusted or altered worker-node software from operating beneath Kubernetes workloads.

External Mappings

FrameworkIDRelationshipRemarks
CWECWE-494relates-toDownload of Code Without Integrity Check
MITRE-ATT&CKT1542.003relates-toPre-OS Boot - Bootkit