1"use strict";(self.webpackChunkk_3_s_docs=self.webpackChunkk_3_s_docs||[]).push([[1475],{6031:(e,s,n)=>{n.r(s),n.d(s,{assets:()=>d,contentTitle:()=>o,default:()=>u,frontMatter:()=>c,metadata:()=>t,toc:()=>l});const t=JSON.parse('{"id":"security/security","title":"Security","description":"This section describes the methodology and means of securing a K3s cluster. It\'s broken into 2 sections. These guides assume k3s is running with embedded etcd.","source":"@site/docs/security/security.md","sourceDirName":"security","slug":"/security/","permalink":"/security/","draft":false,"unlisted":false,"editUrl":"https://github.com/k3s-io/docs/edit/main/docs/security/security.md","tags":[],"version":"current","lastUpdatedAt":1789781277000,"frontMatter":{"title":"Security"},"sidebar":"mySidebar","previous":{"title":"Rolling Back K3s","permalink":"/upgrades/roll-back"},"next":{"title":"Secrets Encryption","permalink":"/security/secrets-encryption"}}');var i=n(74848),r=n(28453);const c={title:"Security"},o=void 0,d={},l=[];function a(e){const s={a:"a",li:"li",p:"p",ul:"ul",...(0,r.R)(),...e.components};return(0,i.jsxs)(i.Fragment,{children:[(0,i.jsx)(s.p,{children:"This section describes the methodology and means of securing a K3s cluster. It's broken into 2 sections. These guides assume k3s is running with embedded etcd."}),"\n",(0,i.jsx)(s.p,{children:"First the hardening guide provides a list of security best practices to secure a K3s cluster."}),"\n",(0,i.jsxs)(s.ul,{children:["\n",(0,i.jsx)(s.li,{children:(0,i.jsx)(s.a,{href:"/security/hardening-guide",children:"Hardening Guide"})}),"\n"]}),"\n",(0,i.jsx)(s.p,{children:"Second, is the self assessment to validate a hardened cluster. We currently have tw
1o different assessments available:"}),"\n",(0,i.jsxs)(s.ul,{children:["\n",(0,i.jsxs)(s.li,{children:["\n",(0,i.jsxs)(s.p,{children:[(0,i.jsx)(s.a,{href:"/security/self-assessment-1.9",children:"CIS 1.9 Benchmark Self-Assessment Guide"}),", for K3s version v1.27-v1.29"]}),"\n"]}),"\n",(0,i.jsxs)(s.li,{children:["\n",(0,i.jsxs)(s.p,{children:[(0,i.jsx)(s.a,{href:"/security/self-assessment-1.10",children:"CIS 1.10 Benchmark Self-Assessment Guide"}),", for K3s version v1.28-v1.31"]}),"\n"]}),"\n",(0,i.jsxs)(s.li,{children:["\n",(0,i.jsxs)(s.p,{children:[(0,i.jsx)(s.a,{href:"/security/self-assessment-1.11",children:"CIS 1.11 Benchmark Self-Assessment Guide"}),", for K3s version v1.29-v1.34"]}),"\n"]}),"\n"]})]})}function u(e={}){const{wrapper:s}={...(0,r.R)(),...e.components};return s?(0,i.jsx)(s,{...e,children:(0,i.jsx)(a,{...e})}):a(e)}},28453:(e,s,n)=>{n.d(s,{R:()=>c,x:()=>o});var t=n(96540);const i={},r=t.createContext(i);function c(e){const s=t.useContext(r);return t.useMemo((function(){return"function"==typeof e?e(s):{...s,...e}}),[s,e])}function o(e){let s;return s=e.disableParentContext?"function"==typeof e.components?e.components(i):e.components||i:c(e.components),t.createElement(r.Provider,{value:s},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.