Skip to main content

💼 6.4.1 Ensure legacy Compute Engine instance metadata APIs are Disabled (Scored)

  • ID: /frameworks/cis-gke-v1.0.0/06/04/01

Description​

Disable the legacy GCE instance metadata APIs for GKE nodes. Under some circumstances, these can be used from within a pod to extract the node's credentials.

Similar​

Sub Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance