Kubermatic logo Docsumentation
  • Products
    Products
    Kubermatic Kubernetes Platform Automated hybrid & multicloud Kubernetes for enterprise demands
    Kubermatic AI New Product End idle GPUs. Securely share AI models across every team
    Kubermatic KubeLB Cloud Native Multi-Tenant Load Balancing
    Kubermatic Virtualization Seamlessly build your private cloud entirely with Kubernetes
    Kubermatic Developer Platform Empower Developers and Accelerate Innovation
    Kubermatic SecureGuard Protect and manage secrets with open-source transparency
    Kubermatic KubeOne Installation and support for your single Kubernetes cluster
    Kubermatic Kubernetes Subscription Upstream Kubernetes support
    Services
    Professional Services How we accelerate your growth
    Kubermatic Kubernetes Platform
    Edge VMware vSphere KubeVirt Static BareMetal Dynamic BareMetal ARM
    On-Prem VMware vSphere Nutanix OpenStack KubeVirt Static BareMetal Dynamic BareMetal
    Cloud AWS Azure Google Cloud Open Telekom Cloud Alibaba Cloud Hetzner Cloud DigitalOcean Equinix Metal KubeVirt
    Kubermatic AI

    A unified AI platform for enterprises, neoclouds, and sovereign AI providers. Turn fragmented GPU infrastructure into shared AI services and maximize GPU utilization across on-prem, cloud, and sovereign environments.

    Kubermatic KubeLB

    Welcome to Kubermatic KubeLB, the next-generation application delivery platform designed for cloud-native architectures. As cloud-native have evolved, Kubermatic KubeLB offers a multi-tenancy approach to load balancing, providing seamless scalability, security, and management for distributed applications and teams.

    Kubermatic Virtualization

    Simplify your operations and streamline your infrastructure with a platform that integrates Kubernetes and virtualized workloads. Enjoy enhanced networking and storage capabilities to fully support your organization’s cloud needs.

    Kubermatic Developer Platform

    Maximize developer productivity and accelerate innovation with Kubermatic Developer Platform (KDP). Powered by Kubernetes API and based on CNCF Sandbox project kcp, our cutting-edge internal developer platform enables the seamless creation and management of services backed by a centralized catalog.

    Kubermatic SecureGuard

    KubeSG is the open-source, unified secrets management solution that simplifies security across all environments. By combining the power of OpenBao with the integration of the External Secrets Operator, it enables automated, breakage-free secret rotation and provides a developer-friendly workflow.

    Kubermatic KubeOne
    Edge VMware vSphere Static BareMetal ARM
    On-Prem VMware vSphere OpenStack Static BareMetal
    Cloud AWS Azure Google Cloud Open Telekom Cloud Alibaba Cloud Hetzner Cloud DigitalOcean Equinix Metal
    Kubermatic Kubernetes Subscription
    Edge VMware vSphere Nutanix
    On-Prem VMware vSphere Nutanix OpenStack
    Cloud AWS Azure Google Cloud Open Telekom Cloud Alibaba Cloud
    Professional Services

    Our Kubernetes experts architect, migrate, and build inhouse competency to bring your cloud native stack into production. Kubermatic is a CNCF Certified Service Provider and Training Partner.

  • Solutions
    By Industry
    Defence
    Public Sector
    Manufacturing
    Telecom
    By Use Case
    Automate with AI
    Implement Platform Engineering
    Control Your Data Sovereignty
    Move Beyond VMware
    Explore All Solutions
  • Customers
  • Resources
    Knowledge base
    Blog
    Cloud Native FAQ
    Kubermatic Learn
    Community
    Kubermatic Community
    Events
    Explore All Resources
  • Company
    About Kubermatic
    Partners
    Press
    Careers
    Contact Us
  • Book a Demo
    • Products
      Kubermatic Kubernetes Platform
      • Features
      • Why Kubermatic
      • Technology Integrations
    • Kubermatic AI New Product
    • Kubermatic KubeLB
    • Kubermatic Virtualization
    • Kubermatic Developer Platform
    • Kubermatic SecureGuard
    • Kubermatic KubeOne
    • Kubermatic Kubernetes Subscription
    • Services
      Professional Services
    • By Industry
      Defence
    • Public Sector
    • Manufacturing
    • Telecom
    • By Use Case
      Automate with AI
    • Implement Platform Engineering
    • Control Your Data Sovereignty
    • Move Beyond VMware
    • Explore All Solutions
  • Customers
    • Knowledge base
      Blog
    • Cloud Native FAQ
    • Learn
    • Community
      Contribution
    • Events
    • Full resource library
    • About Kubermatic
    • Partners
    • Press
    • Careers
    • Contact Us
Book a Demo
  • Quick Start
  • Creating a Kubernetes Cluster
  • Getting KubeOne
  • Architecture
    • Concepts
    • Compatibility
      • Kubernetes
      • Terraform
      • Operating Systems
    • Requirements
      • Infrastructure Management
      • Kubermatic machine-controller
        • Google Cloud Platform
        • Azure
        • AWS
        • vSphere
    • Support Policy
    • Supported providers
    • Operating System Manager
      • Compatibility Matrix
      • Working with Operating System Manager
    • Cluster Reconciliation
  • Tutorials & How-tos
    • Creating a Kubernetes Cluster
    • Creating a Kubernetes Cluster on Bare-metal
    • Creating a Cluster with OIDC Authentication & Audit Logging
    • Upgrading Clusters
    • Unprovisioning Clusters
    • How To Contribute to Kubermatic KubeOne
    • Upgrading
      • Upgrading from KubeOne 1.12 to 1.13
      • Upgrading from 1.11 to 1.12
      • Upgrading from 1.10 to 1.11
      • Upgrading from 1.9 to 1.10
      • Upgrading from 1.8 to 1.9
      • Upgrading from 1.7 to 1.8
      • Upgrading from 1.5 to 1.6
      • Upgrading from 1.4 to 1.5
      • Upgrading from 1.3 to 1.4
      • Upgrading from 1.2 to 1.3
  • Guides
    • Certificate Management
    • Helm integration
    • Using Kubernetes Autoscaler with KubeOne Cluster
    • All-in-one Cluster
    • Monitoring Etcd Ring and Replacing Corrupted Members
    • All In One Node
    • Migrating to the KubeOneCluster v1beta2 API
    • Overwriting Image Registries
    • Using Mirror Registries
    • Enabling Kubernetes Encryption Providers
    • Using Example Terraform Configs
    • Configuring Credentials
    • Configuring SSH
    • Manual Cluster Recovery
    • Static Nodes
    • Static Workers
    • Addons
    • Manual Cluster Repair
    • Proxy support
    • Using machine-controller
  • Security
    • CIS Benchmarking
      • Benchmark on Kubernetes 1.33 with KubeOne 1.11.2
      • Benchmark on Kubernetes 1.27 with KubeOne 1.7.3
      • Benchmark on Kubernetes 1.29 with KubeOne 1.8.0
    • Personally Identifiable Information Analysis: Kubernetes and KubeOne System Logs
  • References
    • Terraform Integration
    • v1beta2 API Reference
    • v1beta3 API Reference
  • Examples
    • Load Balancing in Highly-Available Clusters
    • Backups Addon
    • External CNI
  • Cheat Sheets
    • Production Recommendations
    • Rolling Restart MachineDeploments
  • Known Issues
Imprint
Edit this page

Security

Table of Content

  • CIS Benchmarking
    • Benchmark on Kubernetes 1.33 with KubeOne 1.11.2
      • Benchmark on Kubernetes 1.27 with KubeOne 1.7.3
        • Benchmark on Kubernetes 1.29 with KubeOne 1.8.0
        • Personally Identifiable Information Analysis: Kubernetes and KubeOne System Logs