Hands-on Lab·Kubernetes and Cloud Native Security Associate
CIS Benchmark Assessment with kube-bench
The CIS Kubernetes Benchmark is the compliance framework KCSA names, and kube-bench is how it is run. This guide runs it against the control plane, a worker and the policy section, reads the failures, checks one of them by hand - and finds that the section that matters most is the one a tool cannot score.
Compliance and Frameworks Guide 38 of 42 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 18 min
- Reviewed25 August 2026
Written against the versions above. kube-bench v0.10.7, run as a Job. It selects the benchmark version from the cluster version automatically. The scanner needs the control-plane node and read-only host mounts, which makes it a privileged workload.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
-
Running the benchmark against the control plane
-
The nine failures, four of which are one thing
-
What WARN actually means
-
Checking one finding by hand, and the fix it hands you
-
The same benchmark, pointed at a worker
-
The section a tool cannot score