Set Up Kubernetes Authentication

Create a Kubernetes authentication record for a Kubernetes instance running on a Unix host, add the Kubernetes 1.x technology in your policy, and scan it for compliance. You also need a Unix record for the host on which Kubernetes is installed.

This record type is only available in accounts with PA or SCA and is only supported for compliance scans.

Which technologies are supported?

For the most current list of supported authentication technologies and the versions that have been certified for VM and PA by record type, refer to the following article: 

Authentication Technologies Matrix

How do I get started?

- Go to Scans > Authentication.

- Check that you have a Unix record already defined for the host on which Kubernetes is installed.

- Create a Kubernetes record for the same host. Go to New > Applications > Kubernetes.

Note: If the Network Support feature is enabled, then the Unix record must have the same network selected as the Kubernetes record.

Tell me about user permissionsTell me about user permissions

Managers can add authentication records.

Unit Managers must be granted these permissions:
- Manage PA module / Manage SCA module
- Create/edit authentication records/vaults

Your record settings

We need to know the absolute path of the kubectl command and of the Kubernetes configuration file present on your Unix host. While creating a Kubernetes authentication record, on the Unix Configuration tab, you can specify these paths in the Bin Path and the Conf Path fields. If you leave these fields blank, our service auto-discovers the paths.

Good to Know - It is possible that we can't find the paths and this might result in some configurations not found.

Do you have Tag Support enabled?

If your subscription has Tag Support for Authentication Records enabled, then you'll see additional options for specifying hosts using asset tags. Choose an asset type and then provide IPs or tags to the record. Your asset type options are: IPs/Ranges, IP Range in Tag Rule and Asset Tags.

For domain level authentication, you can only add assets when the domain type is NetBIOS, User-Selected IPs. The Assets section is disabled when the domain type is NetBIOS, Service-Selected IPs, or Active Directory.  

Asset Type: IPs/Ranges
Use this option to add IP addresses/ranges to the record. Enter the IP addresses/ranges in the field provided.

Asset Type: IP Range in Tag Rule
Use this option to add tags that have IP address ranges defined in the tag rule. All IP addresses defined in the tag rule will be associated with the record, including IPs that don’t already have the tag assigned. Click Add Tag to pick tags to include or exclude. Note that only tags with the dynamic tag rule “IP Address in Range(s)” will be available in the tag selector.

Asset Type: Asset Tags
Use this option to add tags to the record for the assets you want included. IP addresses with the selected tags already assigned will be associated with the record. Click Add Tag to pick tags to include or exclude.

Learn more about tag support for authentication records