Skip to main content

Controllers Reconcile Unauthorized Cluster State

CCC.K8S.TH13

A controller or scheduled workload granted excessive scope may repeatedly create or restore unauthorized resources and configuration through its reconciliation loop. Manual remediation can then be overwritten, restoring unsafe cluster state that exposes workload data or interferes with service availability.

Related Capabilities

IDTitleDescription
CCC.K8S.CP06Declarative Workload OrchestrationThe service automatically reconciles Kubernetes workload resources toward their user-declared state by scheduling, restarting, and replacing containers as needed.
CCC.K8S.CP14Managed Cluster ExtensionsThe service can manage the installation and lifecycle of supported extensions for networking, storage, policy, observability, and workload management.

Related Controls

IDTitleDescription
CCC.K8S.CN02Enforce Least-Privilege Cluster AuthorizationApply least privilege across cloud and Kubernetes authorization so identities receive only the permissions required for their cluster responsibilities.
CCC.K8S.CN11Protect Admission Control EnforcementApply mandatory cluster security policy to every workload path and prevent its scope or enforcement configuration from being bypassed or modified without authorization.

External Mappings

FrameworkIDRelationshipRemarks
CWECWE-284relates-toImproper Access Control
MITRE-ATT&CKT1053.007relates-toScheduled Task or Job - Container Orchestration Job
MITRE-ATT&CKT1609relates-toContainer Administration Command