Additional hardening recommendations

Additional hardening measures for nodes, cluster networking, cluster administration, and application configuration.
Default hardening applied automatically during
FactoryTalk® Optix™
High Availability
cluster installation includes WireGuard encryption between nodes, secrets encryption at rest, Kubernetes audit logging, restricted
kubeconfig
file permissions, host firewall rules, and pod anti-affinity.
Apply these additional manual hardening recommendations:
Node and OS hardening
Apply the standard Ubuntu node and operating system hardening baseline before cluster installation. Limit access, remove unneeded services, and keep security updates current.
Disk encryption
Enable disk encryption on each node before cluster installation to protect K3s data and persistent application data at rest.
K3s agent credentials
Protect credentials under
/var/lib/rancher/k3s/agent/
with restricted file permissions and protection at rest.
Cluster network exposure
Limit cluster and application ports to required sources only, and keep cluster traffic on the dedicated local network segment that supports the VIP and failover.
Cluster administration
Restrict SSH and cluster administration access, rotate the node-join token after initial setup, and monitor for unexpected node joins.
Application configuration
In
FactoryTalk Optix
Studio, use HTTPS for the Web Presentation Engine, TLS for MQTT when MQTT is used, and an OPC UA security mode for the Runtime OPC UA Server.
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal