Rule ID
SV-285761r1272704_rule
STIG
Rancher Government Solutions (RGS) Harvester Government CTR Security Technical Implementation GuideVersion
V1R1
Harvester Government platform will offer services to users and these services share resources available on the hosting system. To share the resources in a manner that does not exhaust or over use resources, it is necessary for the container platform to have mechanisms that allow developers to size their containers to provide minimum and maximum amounts. If there is no mechanism to specify limits, container services can cause denial of service (DoS) by over usage. Satisfies: SRG-APP-000246-CTR-000605, SRG-APP-000247-CTR-000330
Verify the Harvester Government platform enforces container resource limits at the project or namespace level for all projects and namespaces within the cluster. 1. Access the Rancher MCM managing Harvester Government. Navigate to the hamburger menu >> select the target cluster >> Cluster >> Projects/Namespaces. 2. For each applicable project or namespace, select the ellipsis (…) to the right of the project or namespace name. 3. Select "Edit Config". 4. Open the "Container Resource Limits" configuration section. If resource limits (CPU and memory) are not defined for the project or namespace, this is a finding. If configured limits do not align with organizational requirements or are not appropriate for the deployed workloads, this is a finding.
Configure the Harvester Government platform container resource limits. 1. Access the Rancher MCM managing Harvester Government. Navigate to the hamburger menu >> select the target cluster >> Cluster >> Projects/Namespaces. 2. For each applicable project or namespace, select the ellipsis (…) to the right of the project or namespace name. 3. Select "Edit Config". 4. Open the "Container Resource Limits" configuration section. 5. Enter the appropriate resource limits and click "Save".