Rule ID
SV-285763r1272726_rule
STIG
Rancher Government Solutions (RGS) Harvester Government CTR Security Technical Implementation GuideVersion
V1R1
CCIs
The Rancher Harvester Government platform must be centrally managed by Rancher MCM to ensure consistent application of configuration management, security policies, and operational controls across the environment. Failure to manage Harvester through Rancher MCM results in decentralized administration, increasing the risk of configuration drift, inconsistent security settings, and unauthorized or untracked changes to system components. Without centralized management, there is limited visibility into system state, reduced ability to enforce standardized baselines, and diminished auditability of administrative actions. Rancher MCM provides a unified control plane for managing Harvester clusters, enabling centralized enforcement of security configurations, role-based access control (RBAC), monitoring, logging, and lifecycle management. This ensures that all system changes are governed, traceable, and aligned with organizational policies and approved baselines. In the absence of centralized management, the platform may operate outside of approved configuration management processes, increasing the likelihood of misconfigurations, delayed remediation of vulnerabilities, and reduced ability to maintain compliance with organizational and regulatory requirements. Satisfies: SRG-APP-000378-CTR-000885, SRG-APP-000023-CTR-000055, SRG-APP-000024-CTR-000060, SRG-APP-000025-CTR-000065, SRG-APP-000033-CTR-000090, SRG-APP-000033-CTR-000095, SRG-APP-000033-CTR-000100, SRG-APP-000038-CTR-000105, SRG-APP-000039-CTR-000110, SRG-APP-000065-CTR-000115, SRG-APP-000090-CTR-000155, SRG-APP-000118-CTR-000240, SRG-APP-000119-CTR-000245, SRG-APP-000120-CTR-000250, SRG-APP-000121-CTR-000255, SRG-APP-000122-CTR-000260, SRG-APP-000123-CTR-000265, SRG-APP-000133-CTR-000290, SRG-APP-000133-CTR-000295, SRG-APP-000133-CTR-000300, SRG-APP-000133-CTR-000305, SRG-APP-000133-CTR-000310, SRG-APP-000148-CTR-000335, SRG-APP-000148-CTR-000340, SRG-APP-000148-CTR-000345, SRG-APP-000148-CTR-000350, SRG-APP-000149-CTR-000355, SRG-APP-000150-CTR-000360, SRG-APP-000151-CTR-000365, SRG-APP-000152-CTR-000370, SRG-APP-000153-CTR-000375, SRG-APP-000163-CTR-000395, SRG-APP-000164-CTR-000400, SRG-APP-000166-CTR-000410, SRG-APP-000167-CTR-000415, SRG-APP-000168-CTR-000420, SRG-APP-000169-CTR-000425, SRG-APP-000170-CTR-000430, SRG-APP-000173-CTR-000445, SRG-APP-000174-CTR-000450, SRG-APP-000177-CTR-000465, SRG-APP-000185-CTR-000490, SRG-APP-000211-CTR-000530, SRG-APP-000233-CTR-000585, SRG-APP-000243-CTR-000600, SRG-APP-000317-CTR-000735, SRG-APP-000318-CTR-000740, SRG-APP-000340-CTR-000770, SRG-APP-000345-CTR-000785, SRG-APP-000378-CTR-000880, SRG-APP-000378-CTR-000890, SRG-APP-000380-CTR-000900, SRG-APP-000389-CTR-000925, SRG-APP-000391-CTR-000935, SRG-APP-000400-CTR-000960, SRG-APP-000402-CTR-000970, SRG-APP-000516-CTR-000790, SRG-APP-000705-CTR-000110, SRG-APP-000820-CTR-000170, SRG-APP-000825-CTR-000180, SRG-APP-000830-CTR-000190, SRG-APP-000835-CTR-000200, SRG-APP-000840-CTR-000210, SRG-APP-000845-CTR-000220, SRG-APP-000855-CTR-000240, SRG-APP-000860-CTR-000250, SRG-APP-000865-CTR-000260, SRG-APP-000910-CTR-000300
Verify Harvester Government is managed by Rancher MCM. 1. Access the Harvester Management UI using system administrator credentials. Navigate to Settings >> Advanced. Verify the cluster-registration-url is configured and points to a legitimate Rancher MCM instance. If Harvester is not registered to or managed by a Rancher MCM instance, this is a finding. If administrative access to Harvester is performed outside of Rancher MCM, this is a finding. 2. Verify Rancher MCM Authentication Configuration. Access the Rancher Multi-Cluster Manager (MCM) UI and navigate to the hamburger menu >> Users & Authentication >> Auth Provider. If no authentication provider is configured in Rancher MCM; OR The configured authentication provider does not enforce multi-factor authentication (MFA); OR The authentication mechanism does not meet DoW-approved authentication requirements (e.g., PKI-based or equivalent strong authentication), this is a finding.
Register Harvester Government to Rancher MCM: 1. Log in to Rancher MCM as an admin user. 2. On the left menu, navigate to "Virtualization Management" and click "Import Existing" in the upper-left corner. 3. Enter a name for the Harvester cluster and click "Create". 4. Follow instructions in the dialogue to copy the registration URL to the Harvester cluster. 5. Ensure Rancher MCM is using an authentication provider that meets organizational requirements and is using an authentication provider that leverages multifactor authentication.