This is an overarching guide to further harden the security posture of a Cray System Management (CSM) system.
If a subset of the steps in this procedure were completed as a consequence of an install, upgrade, or other guidance, then it is safe to skip that subset following a review.
None.
Change passwords and credentials.
Perform procedures in Change Passwords and Credentials.
Randomize iPXE binary name.
Perform procedures in Customize iPXE Binary Names.
(Optional) Enable Spire and OPA xname validation.
Perform procedures in xname validation.
(Optional) Enable Kubernetes API encryption.
Perform procedures in Kubernetes Encryption.
(Optional) Change Keycloak OAuth token lifetime.
Perform procedures in Change Keycloak token lifetime.
(Optional) Remove Kiali.
Perform procedures in Remove Kiali.
(Optional) Kubernetes API audit log file parameter settings.
If Kubernetes API Auditing is enabled, then it is recommended to set --audit-log-maxage to 30 or appropriate value
and --audit-log-maxsize parameter to 100 or appropriate value.
For more information on setting the audit parameters refer Audit parameter settings.