Kubernetes and Cloud Native Associate (KCNA)Cloud Native ObservabilityMedium
A security operations center (SOC) team needs to audit all administrative actions performed within their Kubernetes cluster, including who made changes, when, and from where. This data is critical for compliance and forensic analysis. Which specific type of log within Kubernetes provides this granular information about API server requests?
- AKubelet logs
- BContainer logs (stdout/stderr)
- Ckube-proxy logs
- Dkube-apiserver audit logs
Show answer & explanationAnswer & explanation
Correct answer: D. kube-apiserver audit logs
Kube-apiserver audit logs are specifically designed to record requests made to the Kubernetes API server. These logs capture detailed information about who performed an action, what action was performed, when it happened, and from which IP address, making them indispensable for security auditing and compliance. Kubelet logs are for node agents, container logs for applications, and kube-proxy logs for networking.
Why the other options are wrong
- A. Kubelet logs relate to the node agent's operations, not API server administrative actions.
- B. Container logs are for application output, not Kubernetes administrative actions.
- C. Kube-proxy logs relate to network proxying and service discovery, not API server access auditing.
Kubernetes Audit Logs
A stream of chronologically ordered records of API server requests, used for security auditing, compliance, and forensic analysis within a Kubernetes cluster.
- Records who, what, when, and from where for API server interactions.
- Can be configured for different levels of verbosity (e.g., metadata, request, response).
- Essential for security and regulatory compliance in production clusters.
Memory trick: Audit logs are the security camera for the API server.