The Kubernetes etcd must have file permissions set to 644 or more restrictive.

Severity
Group ID
Group Title
Version
Rule ID
Date
STIG Version
mediumV-242459SRG-APP-000516-CTR-001335CNTR-K8-003260SV-242459r961863_rule2025-02-202
Description
The Kubernetes etcd key-value store provides a way to store data to the Control Plane. If these files can be changed, data to API object and Control Plane would be compromised.
ℹ️ Check
Review the permissions of the Kubernetes etcd by using the command: ls -AR /var/lib/etcd/* If any of the files have permissions more permissive than "644", this is a finding.
✔️ Fix
Change the permissions of the manifest files to "644" by executing the command: chmod -R 644 /var/lib/etcd/*