Cassandra cluster should use password authentication
High
Azure
General
cassandraclusters-cassandra-cluster-password-authe
Applies to
Microsoft.DocumentDB/cassandraClusters
What CGPulse checks
A resource passes this rule when authenticationMethod must equal Cassandra. Anything else is reported as a finding with the evaluated property value attached as evidence.
How to fix it
Configure Cassandra authentication to enforce access control for all client connections. In AWS Console: Keyspaces > configure authentication settings. See: https://docs.aws.amazon.com/keyspaces/latest/devguide/authentication.html
CLI
az managed-cassandra cluster update --ids "{id}" --authentication-method CassandraTerraform
resource "azurerm_cosmosdb_cassandra_cluster" "{name}" {
name = "{name}"
resource_group_name = "{rg}"
location = var.location
delegated_management_subnet_id = "/subscriptions/{sub}/resourceGroups/{rg}/providers/Microsoft.Network/virtualNetworks/{vnet}/subnets/{subnet}"
default_admin_password = "changeme"
authentication_method = "Cassandra"
}
Compliance frameworks
Is your environment compliant with this rule?
CGPulse checks it — and 621 others — against your Azure and AWS accounts with read-only access.
Related Azure rules
- Action Group should be enabled
- Activity Log Alert should be enabled
- AKS cluster logs should be sent to Log Analytics
- AKS cluster must enable RBAC
- AKS cluster must enable RBAC
- AKS cluster should be a private cluster
- AKS cluster should disable local accounts
- AKS cluster should enable Azure RBAC for Kubernetes