Concepts·Kubernetes and Cloud Native Security Associate
Audit Logging and Cluster Records
Audit logging is a Domain 3 competency and this cluster has none - which makes it a good place to measure the gap precisely. This guide establishes what IS recorded, how long it survives, and why the apiserver's own log is not an audit trail.
Security Fundamentals Guide 25 of 42 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 14 min
- Reviewed25 August 2026
Written against the versions above. kubeadm sets no `--audit-policy-file` and no `--audit-log-path`, so auditing is off. `--event-ttl` is likewise unset, so events are retained for one hour.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 10 - where the missing flags would go.
-
Events, which are not an audit trail
-
How long they last, and what is not configured
-
Why the apiserver's own log is not the answer