Concepts·Kubernetes and Cloud Native Security Associate
Audit Logging and Cluster Records
Audit logging is a Domain 3 competency and this cluster has none - which makes it a good place to measure the gap precisely. This guide establishes what IS recorded, how long it survives, and why the apiserver's own log is not an audit trail.
Security Fundamentals Guide 25 of 42 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1
- Built withkubeadm v1.36.3
- TimeAbout 14 min
kubeadm sets no --audit-policy-file and no --audit-log-path, so auditing is off. --event-ttl is likewise unset, so events are retained for one hour.
- Host kernel7.0.0-29
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
This guide includes
Use this when you have to say whether a cluster keeps an audit trail. This matters because a default kubeadm cluster keeps none at all - Events look like one, expire within the hour, and are not it.
- reading what the cluster does record about its own activity
- finding how long Events last, and what is simply not configured
- reading the API server's own log, and noticing what is missing from it
Before you start
- guide 10 - where the missing flags would go.
-
Events, which are not an audit trail
-
How long they last, and what is not configured
-
Why the apiserver's own log is not the answer