`kubectl debug`로 Kubernetes 노드에서 CIS 규정 준수 보고서 만들기
kubectl debug로 Kubernetes 노드에서 CIS 규정 준수 보고서 만들기
Amazon EKS 노드에서 CIS(Center for Internet Security, 인터넷 보안 센터) 규정 준수 보고서를 생성하는 방법을 알아봐요. kubectl debug 명령으로 Kubernetes 노드에 임시 디버깅 컨테이너를 만들고, apiclient 도구를 이용해 CIS 규정 준수 검사를 실행할 수 있어요. EKS Auto Mode 노드의 운영체제인 Bottlerocket OS에 포함된 도구를 사용하니까 별도 설치 없이 바로 써볼 수 있답니다.
출처: 문서
본문
kubectl debug 명령을 사용하면 Kubernetes 노드에 임시 디버깅 컨테이너를 만들고, apiclient 도구로 CIS 규정 준수 검사를 실행할 수 있어요. apiclient는 EKS Auto Mode 노드가 사용하는 Bottlerocket OS의 일부로 제공되는 도구예요.
사전 조건 (Prerequisites)
시작하기 전에 다음 준비가 되어 있어야 해요:
kubectl이 설정된 Amazon EKS 클러스터 접근 권한 (버전은 최소 v1.32.0 이상이어야 해요.kubectl version으로 확인할 수 있어요).- 노드를 디버깅할 수 있는 적절한 IAM 권한.
- 디버그 작업을 허용하는 유효한 프로파일 (예:
sysadmin).
디버깅 프로파일을 사용한 kubectl 디버그 방법에 대한 자세한 내용은 Kubernetes 문서의 Debugging a Pod or Node while applying a profile을 참고해 주세요.
절차 (Procedure)
- 보고서를 실행할 노드의 AWS 인스턴스 ID를 확인해요. 다음 명령으로 클러스터의 노드를 조회하면 이름 컬럼에서
i-로 시작하는 인스턴스 ID를 찾을 수 있어요.
kubectl get nodes
NAME STATUS ROLES AGE VERSION
i-0ea0ba0f8ef9ad609 Ready 62s v1.30.10-eks-1a9dacd
- 다음 명령을 실행해요.
<instance-id>부분은 조회하려는 노드의 인스턴스 ID로 바꿔주세요.
kubectl debug node/<instance-id> -it --profile=sysadmin --image=public.ecr.aws/amazonlinux/amazonlinux:2023 -- bash -c "yum install -q -y util-linux-core; nsenter -t 1 -m apiclient report cis --level 1 --format text"
이 명령의 구성 요소를 하나씩 살펴볼게요:
kubectl debug node/<instance-id>— 지정한 EC2 인스턴스 ID에 디버깅 세션을 만듭니다.-it— TTY(명령줄 셸)를 할당하고 대화형 사용을 위해 stdin을 열어 둡니다.--profile=sysadmin— 적절한 권한을 가진 지정한kubectl프로파일을 사용합니다.--image=public.ecr.aws/amazonlinux/amazonlinux:2023— 디버깅용 컨테이너 이미지로amazonlinux:2023을 사용합니다.bash -c "…"— bash 셸에서 다음 명령들을 실행합니다:yum install -q -y util-linux-core— 필요한 유틸리티 패키지를 조용히 설치합니다.nsenter -t 1 -m—nsenter로 호스트 프로세스(PID 1)의 네임스페이스에 들어갑니다.apiclient report cis --level 1 --format text— CIS 규정 준수 보고서를 level 1 기준으로 텍스트 형식으로 실행합니다.
- 보고서의 텍스트 출력을 확인해요.
출력 해석하기 (Interpreting the output)
이 명령은 각 CIS 컨트롤의 규정 준수 상태를 보여주는 텍스트 기반 보고서를 만듭니다. 출력에는 다음이 포함돼요:
- 개별 CIS 컨트롤 ID
- 각 컨트롤에 대한 설명
- 각 검사에 대한 Pass(통과), Fail(실패), Skip(건너뜀) 상태
- 규정 준수 문제를 설명하는 세부 정보
Bottlerocket 인스턴스에서 보고서를 실행한 예시 출력이에요:
Benchmark name: CIS Bottlerocket Benchmark
Version: v1.0.0
Reference: https://www.cisecurity.org/benchmark/bottlerocket
Benchmark level: 1
Start time: 2025-04-11T01:40:39.055623436Z
[SKIP] 1.2.1 Ensure software update repositories are configured (Manual)
[PASS] 1.3.1 Ensure dm-verity is configured (Automatic)[PASS] 1.4.1 Ensure setuid programs do not create core dumps (Automatic)
[PASS] 1.4.2 Ensure address space layout randomization (ASLR) is enabled (Automatic)
[PASS] 1.4.3 Ensure unprivileged eBPF is disabled (Automatic)
[PASS] 1.5.1 Ensure SELinux is configured (Automatic)
[SKIP] 1.6 Ensure updates, patches, and additional security software are installed (Manual)
[PASS] 2.1.1.1 Ensure chrony is configured (Automatic)
[PASS] 3.2.5 Ensure broadcast ICMP requests are ignored (Automatic)
[PASS] 3.2.6 Ensure bogus ICMP responses are ignored (Automatic)
[PASS] 3.2.7 Ensure TCP SYN Cookies is enabled (Automatic)
[SKIP] 3.4.1.3 Ensure IPv4 outbound and established connections are configured (Manual)
[SKIP] 3.4.2.3 Ensure IPv6 outbound and established connections are configured (Manual)
[PASS] 4.1.1.1 Ensure journald is configured to write logs to persistent disk (Automatic)
[PASS] 4.1.2 Ensure permissions on journal files are configured (Automatic)
Passed: 11
Failed: 0
Skipped: 4
Total checks: 15
이 벤치마크에 대한 자세한 내용은 CIS(Center for Internet Security)의 Kubernetes Benchmark를 참고해 주세요.
관련 리소스 (Related resources)
- Bottlerocket OS 문서의 Bottlerocket CIS Benchmark
- Kubernetes 문서의 Debug Running Pods
- CIS(Center for Internet Security)의 Kubernetes Benchmark