The service may be configured with trusted worker-node images and platform mechanisms that verify node boot integrity before workloads are executed.
Worker Node Integrity Protection
CCC.K8S.CP22
Related Threats
| ID | Title | Description |
|---|---|---|
| CCC.K8S.TH18 | Worker Node Integrity Is Not Verified | Worker nodes created from untrusted or altered images, or started without boot integrity verification, may execute modified software beneath the container runtime. Modified node components can observe workload data and credentials or alter workload execution. Workload confidentiality and integrity may be lost, and node or cluster availability may be reduced. |