Additional hardening recommendations
Additional hardening measures for nodes, cluster networking, cluster administration,
and application configuration.
Default hardening applied automatically during
FactoryTalk® Optix™
High Availability
cluster installation includes WireGuard encryption between
nodes, secrets encryption at rest, Kubernetes audit logging, restricted
kubeconfig
file permissions, host firewall rules, and pod
anti-affinity.Apply these additional manual hardening recommendations:
- Node and OS hardening
- Apply the standard Ubuntu node and operating system hardening baseline before cluster installation. Limit access, remove unneeded services, and keep security updates current.
- Disk encryption
- Enable disk encryption on each node before cluster installation to protect K3s data and persistent application data at rest.
- K3s agent credentials
- Protect credentials under/var/lib/rancher/k3s/agent/with restricted file permissions and protection at rest.
- Cluster network exposure
- Limit cluster and application ports to required sources only, and keep cluster traffic on the dedicated local network segment that supports the VIP and failover.
- Cluster administration
- Restrict SSH and cluster administration access, rotate the node-join token after initial setup, and monitor for unexpected node joins.
- Application configuration
- InFactoryTalk OptixStudio, use HTTPS for the Web Presentation Engine, TLS for MQTT when MQTT is used, and an OPC UA security mode for the Runtime OPC UA Server.
High Availability
Hardening
Disk encryption
Kubernetes
SSH
Provide Feedback