Services, load balancers, ingress resources, or gateways configured with an unintended external scope may make workload endpoints reachable from untrusted networks. Exposed services can then disclose workload data, accept unauthorized changes, or consume capacity needed by legitimate users.
Workload Endpoints are Exposed Unintentionally
CCC.K8S.TH10
Related Capabilities
| ID | Title | Description |
|---|---|---|
| CCC.K8S.CP08 | Workload Traffic Routing | The service can expose and route internal or external traffic to Kubernetes workloads through services, load balancers, ingress controllers, and gateway components. |
Related Controls
| ID | Title | Description |
|---|---|---|
| CCC.K8S.CN06 | Enforce Default-Deny Workload Network Policies | Confine workload communication to flows permitted by explicit, least-privilege network policies, with all other traffic denied by default. |
| CCC.K8S.CN14 | Preserve Kubernetes Audit and Monitoring Records | Maintain complete, externally retained, access-controlled, and monitored records of security-relevant Kubernetes activity and health signals. |