mkdocs support and update docs (#884)
* Delete README.md * Edit readme and separate into different files * Update README.md * Update Running.md * Update CONTRIBUTING.md * Create Contributing.md * Add files via upload * Update Index.md * Rename Flags and Commands.md to Flags_and_commands.md * Rename Index.md to index.md * Create mkdocs.yml * Delete images directory * Update README.md * Update README.md * Update README.md * Update README.md * Update README.md * Update README.md * Create mkdocs-dev.yaml * Create mkdocs-latest.yaml * Update mkdocs.yml * Update mkdocs.yml * Update mkdocs.yml Add yamllint --- * Make it yamllint comply * Make Yamllint comply * Make Yamllint comply * Change description Co-authored-by: Itay Shakury <itay@itaysk.com> * Fix syntax Co-authored-by: Itay Shakury <itay@itaysk.com> * Update docs/Architecture.md Co-authored-by: Itay Shakury <itay@itaysk.com> * Update docs/Architecture.md Co-authored-by: Itay Shakury <itay@itaysk.com> * Update example for test files * Update contributing * Delete Contributing.md * Update Flags_and_commands.md * Change syntax and add source * Update Platforms.md * lower case file names * lower case file names * Lower case file names * Lower case file names * Lower case file names * Lower case file names * Add note about inspect master in some platforms * Add quick start * Lower case files names * Lower case files names * Fixing typo * Remove section about old ocp * Fix typos Co-authored-by: Itay Shakury <itay@itaysk.com>
35
.github/workflows/mkdocs-dev.yaml
vendored
Normal file
@ -0,0 +1,35 @@
|
|||||||
|
---
|
||||||
|
name: Deploy the dev documentation
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
paths:
|
||||||
|
- 'docs/**'
|
||||||
|
- mkdocs.yml
|
||||||
|
branches:
|
||||||
|
- main
|
||||||
|
jobs:
|
||||||
|
deploy:
|
||||||
|
name: Deploy the dev documentation
|
||||||
|
runs-on: ubuntu-18.04
|
||||||
|
steps:
|
||||||
|
- name: Checkout main
|
||||||
|
uses: actions/checkout@v2
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
persist-credentials: true
|
||||||
|
- uses: actions/setup-python@v2
|
||||||
|
with:
|
||||||
|
python-version: 3.x
|
||||||
|
- name: Install dependencies
|
||||||
|
run: |
|
||||||
|
pip install git+https://${GH_TOKEN}@github.com/squidfunk/mkdocs-material-insiders.git
|
||||||
|
pip install mike
|
||||||
|
pip install mkdocs-macros-plugin
|
||||||
|
env:
|
||||||
|
GH_TOKEN: ${{ secrets.MKDOCS_AQUA_BOT }}
|
||||||
|
- name: Setup Git
|
||||||
|
run: |
|
||||||
|
git config user.name "github-actions"
|
||||||
|
git config user.email "github-actions@github.com"
|
||||||
|
- name: Deploy the dev documents
|
||||||
|
run: mike deploy --push dev
|
30
.github/workflows/mkdocs-latest.yaml
vendored
Normal file
@ -0,0 +1,30 @@
|
|||||||
|
---
|
||||||
|
name: Deploy the latest documentation
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
tags:
|
||||||
|
- "v*"
|
||||||
|
jobs:
|
||||||
|
deploy:
|
||||||
|
name: Deploy the latest documentation
|
||||||
|
runs-on: ubuntu-18.04
|
||||||
|
steps:
|
||||||
|
- name: Checkout main
|
||||||
|
uses: actions/checkout@v2
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
persist-credentials: true
|
||||||
|
- uses: actions/setup-python@v2
|
||||||
|
with:
|
||||||
|
python-version: 3.x
|
||||||
|
- name: Install dependencies
|
||||||
|
run: |
|
||||||
|
pip install git+https://${GH_TOKEN}@github.com/squidfunk/mkdocs-material-insiders.git
|
||||||
|
pip install mike
|
||||||
|
pip install mkdocs-macros-plugin
|
||||||
|
env:
|
||||||
|
GH_TOKEN: ${{ secrets.ORG_GITHUB_TOKEN }}
|
||||||
|
- name: Deploy the latest documents
|
||||||
|
run: |
|
||||||
|
VERSION=$(echo ${{ github.ref }} | sed -e "s#refs/tags/##g")
|
||||||
|
mike deploy --push --update-aliases $VERSION latest
|
@ -1,6 +1,8 @@
|
|||||||
Thank you for taking an interest in contributing to kube-bench !
|
Thank you for taking an interest in contributing to kube-bench !
|
||||||
|
|
||||||
## Issues
|
## Contributing, bug reporting, openning issues and starting discussions
|
||||||
|
|
||||||
|
### Issues
|
||||||
|
|
||||||
- Feel free to open an issue for any reason as long as you make it clear if the issue is about a bug/feature/question/comment.
|
- Feel free to open an issue for any reason as long as you make it clear if the issue is about a bug/feature/question/comment.
|
||||||
- Please spend some time giving due diligence to the issue tracker. Your issue might be a duplicate. If it is, please add your comment to the existing issue.
|
- Please spend some time giving due diligence to the issue tracker. Your issue might be a duplicate. If it is, please add your comment to the existing issue.
|
||||||
@ -9,16 +11,69 @@ Thank you for taking an interest in contributing to kube-bench !
|
|||||||
- For questions and bug reports, please include the following information:
|
- For questions and bug reports, please include the following information:
|
||||||
- version of kube-bench you are running (from kube-bench version) along with the command line options you are using.
|
- version of kube-bench you are running (from kube-bench version) along with the command line options you are using.
|
||||||
- version of Kubernetes you are running (from kubectl version or oc version for Openshift).
|
- version of Kubernetes you are running (from kubectl version or oc version for Openshift).
|
||||||
- Verbose log output, by setting the `-v 10` command line option.
|
- Verbose log output, by setting the `-v 3` command line option.
|
||||||
|
|
||||||
## Pull Requests
|
### Bugs
|
||||||
|
|
||||||
|
If you think you have found a bug please follow the instructions below.
|
||||||
|
|
||||||
|
- Open a [new bug](https://github.com/aquasecurity/kube-bench/issues/new?assignees=&labels=&template=bug_report.md) if a duplicate doesn't already exist.
|
||||||
|
- Make sure to give as much information as possible in the following questions
|
||||||
|
- Overview
|
||||||
|
- How did you run kube-bench?
|
||||||
|
- What happened?
|
||||||
|
- What did you expect to happen
|
||||||
|
- Environment
|
||||||
|
- Running processes
|
||||||
|
- Configuration files
|
||||||
|
- Anything else you would like to add
|
||||||
|
- Set `-v 3` command line option and save the log output. Please paste this into your issue.
|
||||||
|
|
||||||
|
|
||||||
|
### Features
|
||||||
|
|
||||||
|
We also use the GitHub discussions to track feature requests. If you have an idea to make kube-bench even more awesome follow the steps below.
|
||||||
|
|
||||||
|
- Open a [new discussion](https://github.com/aquasecurity/kube-bench/discussions/new?category_id=19113743) if a duplicate doesn't already exist.
|
||||||
|
- Remember users might be searching for your discussion in the future, so please give it a meaningful title to helps others.
|
||||||
|
- Clearly define the use case, using concrete examples. For example, I type `this` and kube-bench does `that`.
|
||||||
|
- If you would like to include a technical design for your feature please feel free to do so.
|
||||||
|
|
||||||
|
### Questions
|
||||||
|
|
||||||
|
We also use the GitHub discussions to Q&A.
|
||||||
|
|
||||||
|
- Open a [new discussion](https://github.com/aquasecurity/kube-bench/discussions/new) if a duplicate doesn't already exist.
|
||||||
|
- Remember users might be searching for your discussion in the future, so please give it a meaningful title to helps others.
|
||||||
|
|
||||||
|
|
||||||
|
### Pull Requests
|
||||||
|
|
||||||
|
We welcome pull requests!
|
||||||
|
- Every Pull Request should have an associated Issue, unless you are fixing a trivial documentation issue.
|
||||||
|
- We will not accept changes to LICENSE, NOTICE or CONTRIBUTING from outside the Aqua Security team. Please raise an Issue if you believe there is a problem with any of these files.
|
||||||
|
- Your PR is more likely to be accepted if it focuses on just one change.
|
||||||
|
- Describe what the PR does. There's no convention enforced, but please try to be concise and descriptive. Treat the PR description as a commit message. Titles that start with "fix"/"add"/"improve"/"remove" are good examples.
|
||||||
|
- Please add the associated Issue in the PR description.
|
||||||
|
- Please include a comment with the results before and after your change.
|
||||||
|
- There's no need to add or tag reviewers.
|
||||||
|
- If a reviewer commented on your code or asked for changes, please remember to mark the discussion as resolved after you address it. PRs with unresolved issues should not be merged (even if the comment is unclear or requires no action from your side).
|
||||||
|
- Please include a comment with the results before and after your change.
|
||||||
|
- Your PR is more likely to be accepted if it includes tests (We have not historically been very strict about tests, but we would like to improve this!).
|
||||||
|
- You're welcome to submit a draft PR if you would like early feedback on an idea or an approach.
|
||||||
|
- Happy coding!
|
||||||
|
|
||||||
|
## Testing locally with kind
|
||||||
|
|
||||||
|
Our makefile contains targets to test your current version of kube-bench inside a [Kind](https://kind.sigs.k8s.io/) cluster. This can be very handy if you don't want to run a real Kubernetes cluster for development purposes.
|
||||||
|
|
||||||
|
First, you'll need to create the cluster using `make kind-test-cluster` this will create a new cluster if it cannot be found on your machine. By default, the cluster is named `kube-bench` but you can change the name by using the environment variable `KIND_PROFILE`.
|
||||||
|
|
||||||
|
*If kind cannot be found on your system the target will try to install it using `go get`*
|
||||||
|
|
||||||
|
Next, you'll have to build the kube-bench docker image using `make build-docker`, then we will be able to push the docker image to the cluster using `make kind-push`.
|
||||||
|
|
||||||
|
Finally, we can use the `make kind-run` target to run the current version of kube-bench in the cluster and follow the logs of pods created. (Ctrl+C to exit)
|
||||||
|
|
||||||
|
Every time you want to test a change, you'll need to rebuild the docker image and push it to cluster before running it again. ( `make build-docker kind-push kind-run` )
|
||||||
|
|
||||||
1. Every Pull Request should have an associated Issue, unless you are fixing a trivial documentation issue.
|
|
||||||
1. We will not accept changes to LICENSE, NOTICE or CONTRIBUTING from outside the Aqua Security team. Please raise an Issue if you believe there is a problem with any of these files.
|
|
||||||
1. Your PR is more likely to be accepted if it focuses on just one change.
|
|
||||||
1. Describe what the PR does. There's no convention enforced, but please try to be concise and descriptive. Treat the PR description as a commit message. Titles that start with "fix"/"add"/"improve"/"remove" are good examples.
|
|
||||||
1. Please add the associated Issue in the PR description.
|
|
||||||
1. There's no need to add or tag reviewers.
|
|
||||||
1. If a reviewer commented on your code or asked for changes, please remember to mark the discussion as resolved after you address it. PRs with unresolved issues should not be merged (even if the comment is unclear or requires no action from your side).
|
|
||||||
1. Please include a comment with the results before and after your change.
|
|
||||||
1. Your PR is more likely to be accepted if it includes tests (We have not historically been very strict about tests, but we would like to improve this!).
|
|
||||||
|
416
README.md
@ -17,160 +17,20 @@
|
|||||||
[report-card-img]: https://goreportcard.com/badge/github.com/aquasecurity/kube-bench
|
[report-card-img]: https://goreportcard.com/badge/github.com/aquasecurity/kube-bench
|
||||||
[report-card]: https://goreportcard.com/report/github.com/aquasecurity/kube-bench
|
[report-card]: https://goreportcard.com/report/github.com/aquasecurity/kube-bench
|
||||||
|
|
||||||
<img src="images/kube-bench.png" width="200" alt="kube-bench logo">
|
<img src="docs/images/kube-bench.png" width="200" alt="kube-bench logo">
|
||||||
|
|
||||||
kube-bench is a Go application that checks whether Kubernetes is deployed securely by running the checks documented in the [CIS Kubernetes Benchmark](https://www.cisecurity.org/benchmark/kubernetes/).
|
kube-bench is tool that checks whether Kubernetes is deployed securely by running the checks documented in the [CIS Kubernetes Benchmark](https://www.cisecurity.org/benchmark/kubernetes/).
|
||||||
|
|
||||||
Tests are configured with YAML files, making this tool easy to update as test specifications evolve.
|
Tests are configured with YAML files, making this tool easy to update as test specifications evolve.
|
||||||
|
|
||||||
### Please Note
|
![Kubernetes Bench for Security](/docs/images/output.png "Kubernetes Bench for Security")
|
||||||
|
|
||||||
1. kube-bench implements the [CIS Kubernetes Benchmark](https://www.cisecurity.org/benchmark/kubernetes/) as closely as possible. Please raise issues here if kube-bench is not correctly implementing the test as described in the Benchmark. To report issues in the Benchmark itself (for example, tests that you believe are inappropriate), please join the [CIS community](https://cisecurity.org).
|
### Quick start
|
||||||
|
|
||||||
1. There is not a one-to-one mapping between releases of Kubernetes and releases of the CIS benchmark. See [CIS Kubernetes Benchmark support](#cis-kubernetes-benchmark-support) to see which releases of Kubernetes are covered by different releases of the benchmark.
|
|
||||||
|
|
||||||
1. It is impossible to inspect the master nodes of managed clusters, e.g. GKE, EKS, AKS and ACK, using kube-bench as one does not have access to such nodes, although it is still possible to use kube-bench to check worker node configuration in these environments.
|
|
||||||
|
|
||||||
|
|
||||||
![Kubernetes Bench for Security](https://raw.githubusercontent.com/aquasecurity/kube-bench/main/images/output.png "Kubernetes Bench for Security")
|
|
||||||
|
|
||||||
Table of Contents
|
|
||||||
=================
|
|
||||||
|
|
||||||
- [CIS Kubernetes Benchmark support](#cis-kubernetes-benchmark-support)
|
|
||||||
- [Installation](#installation)
|
|
||||||
- [Running kube-bench](#running-kube-bench)
|
|
||||||
- [Specifying the benchmark or Kubernetes version](#specifying-the-benchmark-or-kubernetes-version)
|
|
||||||
- [Specifying Benchmark sections](#specifying-benchmark-sections)
|
|
||||||
- [Running inside a container](#running-inside-a-container)
|
|
||||||
- [Running in a Kubernetes cluster](#running-in-a-kubernetes-cluster)
|
|
||||||
- [Running in an AKS cluster](#running-in-an-aks-cluster)
|
|
||||||
- [Running in an EKS cluster](#running-in-an-eks-cluster)
|
|
||||||
- [Running on OpenShift](#running-on-openshift)
|
|
||||||
- [Running in an GKE cluster](#running-in-a-gke-cluster)
|
|
||||||
- [Running in an ACK cluster](#running-in-a-ack-cluster)
|
|
||||||
- [Installing from a container](#installing-from-a-container)
|
|
||||||
- [Download and Install binaries](#download-and-install-binaries)
|
|
||||||
- [Installing from sources](#installing-from-sources)
|
|
||||||
- [Output](#output)
|
|
||||||
- [Configuration](#configuration)
|
|
||||||
- [Troubleshooting](#troubleshooting)
|
|
||||||
- [Test config YAML representation](#test-config-yaml-representation)
|
|
||||||
- [Omitting checks](#omitting-checks)
|
|
||||||
- [Roadmap](#roadmap)
|
|
||||||
- [Testing locally with kind](#testing-locally-with-kind)
|
|
||||||
- [Contributing](#contributing)
|
|
||||||
- [Bugs](#bugs)
|
|
||||||
- [Features](#features)
|
|
||||||
- [Pull Requests](#pull-requests)
|
|
||||||
|
|
||||||
|
|
||||||
## CIS Kubernetes Benchmark support
|
|
||||||
|
|
||||||
kube-bench supports the tests for Kubernetes as defined in the [CIS Kubernetes Benchmarks](https://www.cisecurity.org/benchmark/kubernetes/).
|
|
||||||
|
|
||||||
| CIS Kubernetes Benchmark | kube-bench config | Kubernetes versions |
|
|
||||||
|---|---|---|
|
|
||||||
| [1.5.1](https://workbench.cisecurity.org/benchmarks/4892) | cis-1.5 | 1.15- |
|
|
||||||
| [1.6.0](https://workbench.cisecurity.org/benchmarks/4834) | cis-1.6 | 1.16- |
|
|
||||||
| [GKE 1.0.0](https://workbench.cisecurity.org/benchmarks/4536) | gke-1.0 | GKE |
|
|
||||||
| [EKS 1.0.0](https://workbench.cisecurity.org/benchmarks/5190) | eks-1.0 | EKS |
|
|
||||||
| [ACK 1.0.0](https://workbench.cisecurity.org/benchmarks/6467) | ack-1.0 | ACK |
|
|
||||||
| Red Hat OpenShift hardening guide | rh-0.7 | OCP 3.10-3.11 |
|
|
||||||
|
|
||||||
By default, kube-bench will determine the test set to run based on the Kubernetes version running on the machine, but please note that kube-bench does not automatically detect OpenShift and GKE - see the section below on [Running kube-bench](https://github.com/aquasecurity/kube-bench#running-kube-bench).
|
|
||||||
|
|
||||||
The test files for the various versions of CIS Benchmark can be found in directories
|
|
||||||
with same name as the CIS Benchmark versions under `cfg/`, for example `cfg/cis-1.5`.
|
|
||||||
## Installation
|
|
||||||
|
|
||||||
You can choose to
|
|
||||||
* Run kube-bench from inside a container (sharing PID namespace with the host). See [Running inside a container](#running-inside-a-container) for additional details.
|
|
||||||
* Run a container that installs kube-bench on the host, and then run kube-bench directly on the host. See [Installing from a container](#installing-from-a-container) for additional details.
|
|
||||||
* install the latest binaries from the [Releases page](https://github.com/aquasecurity/kube-bench/releases), though please note that you also need to download the config and test files from the `cfg` directory. See [Download and Install binaries](#download-and-install-binaries) for details.
|
|
||||||
* Compile it from source. See [Installing from sources](#installing-from-sources) for details.
|
|
||||||
|
|
||||||
## Running kube-bench
|
|
||||||
|
|
||||||
If you run kube-bench directly from the command line you may need to be root / sudo to have access to all the config files.
|
|
||||||
|
|
||||||
By default kube-bench attempts to auto-detect the running version of Kubernetes, and map this to the corresponding CIS Benchmark version. For example, Kubernetes version 1.15 is mapped to CIS Benchmark version `cis-1.15` which is the benchmark version valid for Kubernetes 1.15.
|
|
||||||
|
|
||||||
kube-bench also attempts to identify the components running on the node, and uses this to determine which tests to run (for example, only running the master node tests if the node is running an API server).
|
|
||||||
|
|
||||||
### Specifying the benchmark or Kubernetes version
|
|
||||||
|
|
||||||
kube-bench uses the Kubernetes API, or access to the `kubectl` or `kubelet` executables to try to determine the Kubernetes version, and hence which benchmark to run. If you wish to override this, or if none of these methods are available, you can specify either the Kubernetes version or CIS Benchmark as a command line parameter.
|
|
||||||
|
|
||||||
You can specify a particular version of Kubernetes by setting the `--version` flag or with the `KUBE_BENCH_VERSION` environment variable. The value of `--version` takes precedence over the value of `KUBE_BENCH_VERSION`.
|
|
||||||
|
|
||||||
For example, run kube-bench using the tests for Kubernetes version 1.13:
|
|
||||||
|
|
||||||
```
|
|
||||||
kube-bench --version 1.13
|
|
||||||
```
|
|
||||||
|
|
||||||
|
|
||||||
You can specify `--benchmark` to run a specific CIS Benchmark version:
|
|
||||||
|
|
||||||
```
|
|
||||||
kube-bench --benchmark cis-1.5
|
|
||||||
```
|
|
||||||
|
|
||||||
**Note:** It is an error to specify both `--version` and `--benchmark` flags together
|
|
||||||
|
|
||||||
### Specifying Benchmark sections
|
|
||||||
|
|
||||||
If you want to run specific CIS Benchmark sections (i.e master, node, etcd, etc...)
|
|
||||||
you can use the `run --targets` subcommand.
|
|
||||||
|
|
||||||
```
|
|
||||||
kube-bench run --targets master,node
|
|
||||||
```
|
|
||||||
|
|
||||||
or
|
|
||||||
|
|
||||||
```
|
|
||||||
kube-bench run --targets master,node,etcd,policies
|
|
||||||
```
|
|
||||||
|
|
||||||
Check the contents of the benchmark directory under `cfg` to see which targets are available for that benchmark. Each file except `config.yaml` represents a target (also known as a `control` in other parts of this documentation).
|
|
||||||
|
|
||||||
The following table shows the valid targets based on the CIS Benchmark version.
|
|
||||||
| CIS Benchmark | Targets |
|
|
||||||
|---|---|
|
|
||||||
| cis-1.5| master, controlplane, node, etcd, policies |
|
|
||||||
| cis-1.6| master, controlplane, node, etcd, policies |
|
|
||||||
| gke-1.0| master, controlplane, node, etcd, policies, managedservices |
|
|
||||||
| eks-1.0| controlplane, node, policies, managedservices |
|
|
||||||
| ack-1.0| master, controlplane, node, etcd, policies, managedservices |
|
|
||||||
|
|
||||||
If no targets are specified, `kube-bench` will determine the appropriate targets based on the CIS Benchmark version and the components detected on the node. The detection is done by verifying which components are running, as defined in the config files (see [Configuration](#configuration).
|
|
||||||
### Running inside a container
|
|
||||||
|
|
||||||
You can avoid installing kube-bench on the host by running it inside a container using the host PID namespace and mounting the `/etc` and `/var` directories where the configuration and other files are located on the host so that kube-bench can check their existence and permissions.
|
|
||||||
|
|
||||||
```
|
|
||||||
docker run --pid=host -v /etc:/etc:ro -v /var:/var:ro -t aquasec/kube-bench:latest --version 1.13
|
|
||||||
```
|
|
||||||
|
|
||||||
> Note: the tests require either the kubelet or kubectl binary in the path in order to auto-detect the Kubernetes version. You can pass `-v $(which kubectl):/usr/local/mount-from-host/bin/kubectl` to resolve this. You will also need to pass in kubeconfig credentials. For example:
|
|
||||||
|
|
||||||
```
|
|
||||||
docker run --pid=host -v /etc:/etc:ro -v /var:/var:ro -v $(which kubectl):/usr/local/mount-from-host/bin/kubectl -v ~/.kube:/.kube -e KUBECONFIG=/.kube/config -t aquasec/kube-bench:latest
|
|
||||||
```
|
|
||||||
|
|
||||||
You can use your own configs by mounting them over the default ones in `/opt/kube-bench/cfg/`
|
|
||||||
|
|
||||||
```
|
|
||||||
docker run --pid=host -v /etc:/etc:ro -v /var:/var:ro -t -v path/to/my-config.yaml:/opt/kube-bench/cfg/config.yam -v $(which kubectl):/usr/local/mount-from-host/bin/kubectl -v ~/.kube:/.kube -e KUBECONFIG=/.kube/config aquasec/kube-bench:latest
|
|
||||||
```
|
|
||||||
|
|
||||||
### Running in a Kubernetes cluster
|
|
||||||
|
|
||||||
|
There are multiple ways to run kube-bench.
|
||||||
You can run kube-bench inside a pod, but it will need access to the host's PID namespace in order to check the running processes, as well as access to some directories on the host where config files and other files are stored.
|
You can run kube-bench inside a pod, but it will need access to the host's PID namespace in order to check the running processes, as well as access to some directories on the host where config files and other files are stored.
|
||||||
|
|
||||||
The supplied `job.yaml` file can be applied to run the tests as a job. For example:
|
The supplied `job.yaml` [file](job.yaml) can be applied to run the tests as a job. For example:
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
$ kubectl apply -f job.yaml
|
$ kubectl apply -f job.yaml
|
||||||
@ -191,268 +51,22 @@ kubectl logs kube-bench-j76s9
|
|||||||
[INFO] 1.1 API Server
|
[INFO] 1.1 API Server
|
||||||
...
|
...
|
||||||
```
|
```
|
||||||
|
For more information and different ways to run kube-bench see [documentation](docs/running.md)
|
||||||
|
### Please Note
|
||||||
|
|
||||||
To run tests on the master node, the pod needs to be scheduled on that node. This involves setting a nodeSelector and tolerations in the pod spec.
|
1. kube-bench implements the [CIS Kubernetes Benchmark](https://www.cisecurity.org/benchmark/kubernetes/) as closely as possible. Please raise issues here if kube-bench is not correctly implementing the test as described in the Benchmark. To report issues in the Benchmark itself (for example, tests that you believe are inappropriate), please join the [CIS community](https://cisecurity.org).
|
||||||
|
|
||||||
The default labels applied to master nodes has changed since Kubernetes 1.11, so if you are using an older version you may need to modify the nodeSelector and tolerations to run the job on the master node.
|
1. There is not a one-to-one mapping between releases of Kubernetes and releases of the CIS benchmark. See [CIS Kubernetes Benchmark support](docs/platforms.md#cis-kubernetes-benchmark-support) to see which releases of Kubernetes are covered by different releases of the benchmark.
|
||||||
### Running in an AKS cluster
|
|
||||||
|
|
||||||
1. Create an AKS cluster(e.g. 1.13.7) with RBAC enabled, otherwise there would be 4 failures
|
|
||||||
|
|
||||||
1. Use the [kubectl-enter plugin](https://github.com/kvaps/kubectl-enter) to shell into a node
|
By default, kube-bench will determine the test set to run based on the Kubernetes version running on the machine.
|
||||||
`
|
- see the following documentation on [Running kube-bench](docs/running.md#running-kube-bench) for more details.
|
||||||
kubectl-enter {node-name}
|
|
||||||
`
|
|
||||||
or ssh to one agent node
|
|
||||||
could open nsg 22 port and assign a public ip for one agent node (only for testing purpose)
|
|
||||||
|
|
||||||
1. Run CIS benchmark to view results:
|
|
||||||
```
|
|
||||||
docker run --rm -v `pwd`:/host aquasec/kube-bench:latest install
|
|
||||||
./kube-bench
|
|
||||||
```
|
|
||||||
kube-bench cannot be run on AKS master nodes
|
|
||||||
|
|
||||||
### Running in an EKS cluster
|
## Contributing
|
||||||
|
Kindly read [Contributing](CONTRIBUTING.md) before contributing.
|
||||||
There is a `job-eks.yaml` file for running the kube-bench node checks on an EKS cluster. The significant difference on EKS is that it's not possible to schedule jobs onto the master node, so master checks can't be performed
|
We welcome PRs and issue reports.
|
||||||
|
|
||||||
1. To create an EKS Cluster refer to [Getting Started with Amazon EKS](https://docs.aws.amazon.com/eks/latest/userguide/getting-started.html) in the *Amazon EKS User Guide*
|
|
||||||
- Information on configuring `eksctl`, `kubectl` and the AWS CLI is within
|
|
||||||
2. Create an [Amazon Elastic Container Registry (ECR)](https://docs.aws.amazon.com/AmazonECR/latest/userguide/what-is-ecr.html) repository to host the kube-bench container image
|
|
||||||
```
|
|
||||||
aws ecr create-repository --repository-name k8s/kube-bench --image-tag-mutability MUTABLE
|
|
||||||
```
|
|
||||||
3. Download, build and push the kube-bench container image to your ECR repo
|
|
||||||
```
|
|
||||||
git clone https://github.com/aquasecurity/kube-bench.git
|
|
||||||
cd kube-bench
|
|
||||||
aws ecr get-login-password --region <AWS_REGION> | docker login --username AWS --password-stdin <AWS_ACCT_NUMBER>.dkr.ecr.<AWS_REGION>.amazonaws.com
|
|
||||||
docker build -t k8s/kube-bench .
|
|
||||||
docker tag k8s/kube-bench:latest <AWS_ACCT_NUMBER>.dkr.ecr.<AWS_REGION>.amazonaws.com/k8s/kube-bench:latest
|
|
||||||
docker push <AWS_ACCT_NUMBER>.dkr.ecr.<AWS_REGION>.amazonaws.com/k8s/kube-bench:latest
|
|
||||||
```
|
|
||||||
4. Copy the URI of your pushed image, the URI format is like this: `<AWS_ACCT_NUMBER>.dkr.ecr.<AWS_REGION>.amazonaws.com/k8s/kube-bench:latest`
|
|
||||||
5. Replace the `image` value in `job-eks.yaml` with the URI from Step 4
|
|
||||||
6. Run the kube-bench job on a Pod in your Cluster: `kubectl apply -f job-eks.yaml`
|
|
||||||
7. Find the Pod that was created, it *should* be in the `default` namespace: `kubectl get pods --all-namespaces`
|
|
||||||
8. Retrieve the value of this Pod and output the report, note the Pod name will vary: `kubectl logs kube-bench-<value>`
|
|
||||||
- You can save the report for later reference: `kubectl logs kube-bench-<value> > kube-bench-report.txt`
|
|
||||||
|
|
||||||
#### Report kube-bench findings to AWS Security Hub
|
|
||||||
|
|
||||||
You can configure kube-bench with the `--asff` option to send findings to AWS Security Hub for any benchmark tests that fail or that generate a warning. See [this page][kube-bench-aws-security-hub] for more information on how to enable the kube-bench integration with AWS Security Hub.
|
|
||||||
|
|
||||||
### Running on OpenShift
|
|
||||||
|
|
||||||
| OpenShift Hardening Guide | kube-bench config |
|
|
||||||
|---|---|
|
|
||||||
| ocp-3.10| rh-0.7 |
|
|
||||||
| ocp-3.11| rh-0.7 |
|
|
||||||
| ocp-4.* | Not supported |
|
|
||||||
|
|
||||||
kube-bench includes a set of test files for Red Hat's OpenShift hardening guide for OCP 3.10 and 3.11. To run this you will need to specify `--benchmark rh-07`, or `--version ocp-3.10` or `--version ocp-3.11`
|
|
||||||
|
|
||||||
when you run the `kube-bench` command (either directly or through YAML).
|
|
||||||
|
|
||||||
There is work in progress on a [CIS Red Hat OpenShift Container Platform Benchmark](https://workbench.cisecurity.org/benchmarks/5248) which we believe should cover OCP 4.* and we intend to add support in kube-bench when it's published.
|
|
||||||
|
|
||||||
### Running in a GKE cluster
|
|
||||||
|
|
||||||
| CIS Benchmark | Targets |
|
|
||||||
|---|---|
|
|
||||||
| gke-1.0| master, controlplane, node, etcd, policies, managedservices |
|
|
||||||
|
|
||||||
kube-bench includes benchmarks for GKE. To run this you will need to specify `--benchmark gke-1.0` when you run the `kube-bench` command.
|
|
||||||
|
|
||||||
To run the benchmark as a job in your GKE cluster apply the included `job-gke.yaml`.
|
|
||||||
|
|
||||||
```
|
|
||||||
kubectl apply -f job-gke.yaml
|
|
||||||
```
|
|
||||||
|
|
||||||
### Running in a ACK cluster
|
|
||||||
|
|
||||||
| CIS Benchmark | Targets |
|
|
||||||
|---|---|
|
|
||||||
| ack-1.0| master, controlplane, node, etcd, policies, managedservices |
|
|
||||||
|
|
||||||
kube-bench includes benchmarks for Alibaba Cloud Container Service For Kubernetes (ACK).
|
|
||||||
To run this you will need to specify `--benchmark ack-1.0` when you run the `kube-bench` command.
|
|
||||||
|
|
||||||
To run the benchmark as a job in your ACK cluster apply the included `job-ack.yaml`.
|
|
||||||
|
|
||||||
```
|
|
||||||
kubectl apply -f job-ack.yaml
|
|
||||||
```
|
|
||||||
|
|
||||||
### Installing from a container
|
|
||||||
|
|
||||||
This command copies the kube-bench binary and configuration files to your host from the Docker container:
|
|
||||||
**binaries compiled for linux-x86-64 only (so they won't run on macOS or Windows)**
|
|
||||||
```
|
|
||||||
docker run --rm -v `pwd`:/host aquasec/kube-bench:latest install
|
|
||||||
```
|
|
||||||
|
|
||||||
You can then run `./kube-bench`.
|
|
||||||
|
|
||||||
### Download and Install binaries
|
|
||||||
|
|
||||||
It is possible to manually install and run kube-bench release binaries. In order to do that, you must have access to your Kubernetes cluster nodes. Note that if you're using one of the managed Kubernetes services (e.g. EKS, AKS, GKE, ACK), you will not have access to the master nodes of your cluster and you can’t perform any tests on the master nodes.
|
|
||||||
|
|
||||||
First, log into one of the nodes using SSH.
|
|
||||||
|
|
||||||
Install kube-bench binary for your platform using the commands below. Note that there may be newer releases available. See [releases page](https://github.com/aquasecurity/kube-bench/releases).
|
|
||||||
|
|
||||||
Ubuntu/Debian:
|
|
||||||
|
|
||||||
```
|
|
||||||
curl -L https://github.com/aquasecurity/kube-bench/releases/download/v0.3.1/kube-bench_0.3.1_linux_amd64.deb -o kube-bench_0.3.1_linux_amd64.deb
|
|
||||||
|
|
||||||
sudo apt install ./kube-bench_0.3.1_linux_amd64.deb -f
|
|
||||||
```
|
|
||||||
|
|
||||||
RHEL:
|
|
||||||
|
|
||||||
```
|
|
||||||
curl -L https://github.com/aquasecurity/kube-bench/releases/download/v0.3.1/kube-bench_0.3.1_linux_amd64.rpm -o kube-bench_0.3.1_linux_amd64.rpm
|
|
||||||
|
|
||||||
sudo yum install kube-bench_0.3.1_linux_amd64.rpm -y
|
|
||||||
```
|
|
||||||
|
|
||||||
Alternatively, you can manually download and extract the kube-bench binary:
|
|
||||||
|
|
||||||
```
|
|
||||||
curl -L https://github.com/aquasecurity/kube-bench/releases/download/v0.3.1/kube-bench_0.3.1_linux_amd64.tar.gz -o kube-bench_0.3.1_linux_amd64.tar.gz
|
|
||||||
|
|
||||||
tar -xvf kube-bench_0.3.1_linux_amd64.tar.gz
|
|
||||||
```
|
|
||||||
|
|
||||||
You can then run kube-bench directly:
|
|
||||||
```
|
|
||||||
kube-bench
|
|
||||||
```
|
|
||||||
|
|
||||||
If you manually downloaded the kube-bench binary (using curl command above), you have to specify the location of configuration directory and file. For example:
|
|
||||||
```
|
|
||||||
./kube-bench --config-dir `pwd`/cfg --config `pwd`/cfg/config.yaml
|
|
||||||
```
|
|
||||||
|
|
||||||
See previous section on [Running kube-bench](#running-kube-bench) for further details on using the kube-bench binary.
|
|
||||||
|
|
||||||
### Installing from sources
|
|
||||||
|
|
||||||
If Go is installed on the target machines, you can simply clone this repository and run as follows (assuming your [`GOPATH` is set](https://github.com/golang/go/wiki/GOPATH)):
|
|
||||||
|
|
||||||
```shell
|
|
||||||
go get github.com/aquasecurity/kube-bench
|
|
||||||
cd $GOPATH/src/github.com/aquasecurity/kube-bench
|
|
||||||
go build -o kube-bench .
|
|
||||||
|
|
||||||
# See all supported options
|
|
||||||
./kube-bench --help
|
|
||||||
|
|
||||||
# Run all checks
|
|
||||||
./kube-bench
|
|
||||||
```
|
|
||||||
|
|
||||||
## Output
|
|
||||||
|
|
||||||
There are four output states:
|
|
||||||
- [PASS] indicates that the test was run successfully, and passed.
|
|
||||||
- [FAIL] indicates that the test was run successfully, and failed. The remediation output describes how to correct the configuration, or includes an error message describing why the test could not be run.
|
|
||||||
- [WARN] means this test needs further attention, for example it is a test that needs to be run manually. Check the remediation output for further information.
|
|
||||||
- [INFO] is informational output that needs no further action.
|
|
||||||
|
|
||||||
Note:
|
|
||||||
- If the test is Manual, this always generates WARN (because the user has to run it manually)
|
|
||||||
- If the test is Scored, and kube-bench was unable to run the test, this generates FAIL (because the test has not been passed, and as a Scored test, if it doesn't pass then it must be considered a failure).
|
|
||||||
- If the test is Not Scored, and kube-bench was unable to run the test, this generates WARN.
|
|
||||||
- If the test is Scored, type is empty, and there are no `test_items` present, it generates a WARN. This is to highlight tests that appear to be incompletely defined.
|
|
||||||
|
|
||||||
## Configuration
|
|
||||||
|
|
||||||
Kubernetes configuration and binary file locations and names can vary from installation to installation, so these are configurable in the `cfg/config.yaml` file.
|
|
||||||
|
|
||||||
Any settings in the version-specific config file `cfg/<version>/config.yaml` take precedence over settings in the main `cfg/config.yaml` file.
|
|
||||||
|
|
||||||
You can read more about `kube-bench` configuration in our [documentation](docs/README.md#configuration-and-variables).
|
|
||||||
|
|
||||||
## Troubleshooting
|
|
||||||
|
|
||||||
Running `kube-bench` with the `-v 3` parameter will generate debug logs that can be very helpful for debugging problems.
|
|
||||||
|
|
||||||
If you are using one of the example `job*.yaml` files, you will need to edit the `command` field, for example `["kube-bench", "-v", "3"]`. Once the job has run, the logs can be retrieved using `kubectl logs` on the job's pod.
|
|
||||||
|
|
||||||
## Test config YAML representation
|
|
||||||
|
|
||||||
The tests (or "controls") are represented as YAML documents (installed by default into `./cfg`). There are different versions of these test YAML files reflecting different versions of the CIS Kubernetes Benchmark. You will find more information about the test file YAML definitions in our [documentation](docs/README.md).
|
|
||||||
|
|
||||||
### Omitting checks
|
|
||||||
|
|
||||||
If you decide that a recommendation is not appropriate for your environment, you can choose to omit it by editing the test YAML file to give it the check type `skip` as in this example:
|
|
||||||
|
|
||||||
```yaml
|
|
||||||
checks:
|
|
||||||
- id: 2.1.1
|
|
||||||
text: "Ensure that the --allow-privileged argument is set to false (Scored)"
|
|
||||||
type: "skip"
|
|
||||||
scored: true
|
|
||||||
```
|
|
||||||
|
|
||||||
No tests will be run for this check and the output will be marked [INFO].
|
|
||||||
|
|
||||||
## Roadmap
|
## Roadmap
|
||||||
|
|
||||||
Going forward we plan to release updates to kube-bench to add support for new releases of the CIS Benchmark. Note that these are not released as frequently as Kubernetes releases.
|
Going forward we plan to release updates to kube-bench to add support for new releases of the CIS Benchmark. Note that these are not released as frequently as Kubernetes releases.
|
||||||
|
|
||||||
We welcome PRs and issue reports.
|
|
||||||
|
|
||||||
## Testing locally with kind
|
|
||||||
|
|
||||||
Our makefile contains targets to test your current version of kube-bench inside a [Kind](https://kind.sigs.k8s.io/) cluster. This can be very handy if you don't want to run a real Kubernetes cluster for development purposes.
|
|
||||||
|
|
||||||
First, you'll need to create the cluster using `make kind-test-cluster` this will create a new cluster if it cannot be found on your machine. By default, the cluster is named `kube-bench` but you can change the name by using the environment variable `KIND_PROFILE`.
|
|
||||||
|
|
||||||
*If kind cannot be found on your system the target will try to install it using `go get`*
|
|
||||||
|
|
||||||
Next, you'll have to build the kube-bench docker image using `make build-docker`, then we will be able to push the docker image to the cluster using `make kind-push`.
|
|
||||||
|
|
||||||
Finally, we can use the `make kind-run` target to run the current version of kube-bench in the cluster and follow the logs of pods created. (Ctrl+C to exit)
|
|
||||||
|
|
||||||
Every time you want to test a change, you'll need to rebuild the docker image and push it to cluster before running it again. ( `make build-docker kind-push kind-run` )
|
|
||||||
|
|
||||||
## Contributing
|
|
||||||
Kindly read [Contributing.md](CONTRIBUTING.md) before contributing. Some instructions for the common contributions are stated below.
|
|
||||||
|
|
||||||
### Bugs
|
|
||||||
|
|
||||||
If you think you have found a bug please follow the instructions below.
|
|
||||||
|
|
||||||
- Please spend a small amount of time giving due diligence to the issue tracker. Your issue might be a duplicate.
|
|
||||||
- Open a [new issue](https://github.com/aquasecurity/kube-bench/issues/new) if a duplicate doesn't already exist.
|
|
||||||
- Note the version of kube-bench you are running (from `kube-bench version`) and the command line options you are using.
|
|
||||||
- Note the version of Kubernetes you are running (from `kubectl version` or `oc version` for OpenShift).
|
|
||||||
- Set `-v 10` command line option and save the log output. Please paste this into your issue.
|
|
||||||
- Remember users might be searching for your issue in the future, so please give it a meaningful title to help others.
|
|
||||||
|
|
||||||
### Features
|
|
||||||
|
|
||||||
We also use the GitHub issue tracker to track feature requests. If you have an idea to make kube-bench even more awesome follow the steps below.
|
|
||||||
|
|
||||||
- Open a [new issue](https://github.com/aquasecurity/kube-bench/issues/new).
|
|
||||||
- Remember users might be searching for your issue in the future, so please give it a meaningful title to helps others.
|
|
||||||
- Clearly define the use case, using concrete examples. For example, I type `this` and kube-bench does `that`.
|
|
||||||
- If you would like to include a technical design for your feature please feel free to do so.
|
|
||||||
|
|
||||||
### Pull Requests
|
|
||||||
|
|
||||||
We welcome pull requests!
|
|
||||||
|
|
||||||
- Your PR is more likely to be accepted if it focuses on just one change.
|
|
||||||
- Please include a comment with the results before and after your change.
|
|
||||||
- Your PR is more likely to be accepted if it includes tests. (We have not historically been very strict about tests, but we would like to improve this!).
|
|
||||||
- You're welcome to submit a draft PR if you would like early feedback on an idea or an approach.
|
|
||||||
- Happy coding!
|
|
||||||
|
|
||||||
[kube-bench-aws-security-hub]: ./docs/asff.md
|
|
||||||
|
25
docs/architecture.md
Normal file
@ -0,0 +1,25 @@
|
|||||||
|
## Test config YAML representation
|
||||||
|
|
||||||
|
The tests (or "controls") are maintained in YAML documents. There are different versions of these test YAML files reflecting different [versions and platforms of the CIS Kubernetes Benchmark](./platforms.md). You will find more information about the test file YAML definitions in our [controls documentation](./controls.md).
|
||||||
|
|
||||||
|
## Kube-bench benchmarks
|
||||||
|
|
||||||
|
The test files for the various versions of Benchmarks can be found in directories
|
||||||
|
with same name as the Benchmark versions under the `cfg` directory next to the kube-bench executable,
|
||||||
|
for example `./cfg/cis-1.5` will contain all test files for [CIS Kubernetes Benchmark v1.5.1](https://workbench.cisecurity.org/benchmarks/4892) which are:
|
||||||
|
master.yaml, controlplane.yaml, node.yaml, etcd.yaml, policies.yaml and config.yaml
|
||||||
|
|
||||||
|
Check the contents of the benchmark directory under `cfg` to see which targets are available for that benchmark. Each file except `config.yaml` represents a target (also known as a `control` in other parts of this documentation).
|
||||||
|
|
||||||
|
The following table shows the valid targets based on the CIS Benchmark version.
|
||||||
|
| CIS Benchmark | Targets |
|
||||||
|
|---|---|
|
||||||
|
| cis-1.5| master, controlplane, node, etcd, policies |
|
||||||
|
| cis-1.6| master, controlplane, node, etcd, policies |
|
||||||
|
| gke-1.0| master, controlplane, node, etcd, policies, managedservices |
|
||||||
|
| eks-1.0| controlplane, node, policies, managedservices |
|
||||||
|
| ack-1.0| master, controlplane, node, etcd, policies, managedservices |
|
||||||
|
| rh-0.7| master,node|
|
||||||
|
| rh-1.0| master, controlplane, node, etcd, policies |
|
||||||
|
|
||||||
|
|
@ -41,7 +41,7 @@ groups:
|
|||||||
text: "Ensure that the --profiling argument is set to false (Scored)"
|
text: "Ensure that the --profiling argument is set to false (Scored)"
|
||||||
audit: "ps -ef | grep kube-scheduler | grep -v grep"
|
audit: "ps -ef | grep kube-scheduler | grep -v grep"
|
||||||
tests:
|
tests:
|
||||||
bin_op: or
|
bin_op: and
|
||||||
test_items:
|
test_items:
|
||||||
- flag: "--profiling"
|
- flag: "--profiling"
|
||||||
set: true
|
set: true
|
||||||
@ -150,11 +150,15 @@ pass a check. This criteria is made up of keywords extracted from the output of
|
|||||||
the `audit` command and operations that compare these keywords against
|
the `audit` command and operations that compare these keywords against
|
||||||
values expected by the CIS Kubernetes Benchmark.
|
values expected by the CIS Kubernetes Benchmark.
|
||||||
|
|
||||||
There are three ways to extract keywords from the output of the `audit` command,
|
There are three ways to run and extract keywords from the output of the command used,
|
||||||
`flag`, `path`, `env`.
|
| Command | Output var |
|
||||||
|
|---|---|
|
||||||
|
| `audit` | `flag` |
|
||||||
|
| `audit_config` | `path` |
|
||||||
|
| `audit_env` | `env` |
|
||||||
|
|
||||||
`flag` is used when the keyword is a command-line flag. The associated `audit`
|
`flag` is used when the keyword is a command-line flag. The associated `audit` command could
|
||||||
command is usually a `ps` command and a `grep` for the binary whose flag we are
|
be any binaries available on the system like `ps` command and a `grep` for the binary whose flag we are
|
||||||
checking:
|
checking:
|
||||||
|
|
||||||
```sh
|
```sh
|
||||||
@ -173,7 +177,7 @@ tests:
|
|||||||
```
|
```
|
||||||
|
|
||||||
`path` is used when the keyword is an option set in a JSON or YAML config file.
|
`path` is used when the keyword is an option set in a JSON or YAML config file.
|
||||||
The associated `audit` command is usually `cat /path/to/config-yaml-or-json`.
|
The associated `audit_command` command is usually `cat /path/to/config-yaml-or-json`.
|
||||||
For example:
|
For example:
|
||||||
|
|
||||||
```yml
|
```yml
|
||||||
@ -189,7 +193,7 @@ tests:
|
|||||||
`env` is used to check if the value is present within a specified environment variable. The presence of `env` is treated as an OR operation, if both `flag` and `env` are supplied it will use either to attempt pass the check.
|
`env` is used to check if the value is present within a specified environment variable. The presence of `env` is treated as an OR operation, if both `flag` and `env` are supplied it will use either to attempt pass the check.
|
||||||
The command used for checking the environment variables of a process **is generated by default**.
|
The command used for checking the environment variables of a process **is generated by default**.
|
||||||
|
|
||||||
If the command being generated is causing errors, you can override the command used by setting `auditEnv` on the check.
|
If the command being generated is causing errors, you can override the command used by setting `audit_env` on the check.
|
||||||
Similarly, if you don't want the environment checking command to be generated or run at all, specify `disableEnvTesting` as true on the check.
|
Similarly, if you don't want the environment checking command to be generated or run at all, specify `disableEnvTesting` as true on the check.
|
||||||
|
|
||||||
The example below will check if the flag `--auto-tls` is equal to false *OR* `ETCD_AUTO_TLS` is equal to false
|
The example below will check if the flag `--auto-tls` is equal to false *OR* `ETCD_AUTO_TLS` is equal to false
|
||||||
@ -202,6 +206,7 @@ The example below will check if the flag `--auto-tls` is equal to false *OR* `ET
|
|||||||
op: eq
|
op: eq
|
||||||
value: false
|
value: false
|
||||||
```
|
```
|
||||||
|
**Note:** flag, path and env will act as OR if more then one present.
|
||||||
|
|
||||||
`test_item` compares the output of the audit command and keywords using the
|
`test_item` compares the output of the audit command and keywords using the
|
||||||
`set` and `compare` fields.
|
`set` and `compare` fields.
|
||||||
@ -220,6 +225,7 @@ The example below will check if the flag `--auto-tls` is equal to false *OR* `ET
|
|||||||
If `set` is true, the check passes only if the keyword is present in the output
|
If `set` is true, the check passes only if the keyword is present in the output
|
||||||
of the audit command, or config file. If `set` is false, the check passes only
|
of the audit command, or config file. If `set` is false, the check passes only
|
||||||
if the keyword is not present in the output of the audit command, or config file.
|
if the keyword is not present in the output of the audit command, or config file.
|
||||||
|
`set` is true by default.
|
||||||
|
|
||||||
`compare` has two fields `op` and `value` to compare keywords with expected
|
`compare` has two fields `op` and `value` to compare keywords with expected
|
||||||
value. `op` specifies which operation is used for the comparison, and `value`
|
value. `op` specifies which operation is used for the comparison, and `value`
|
||||||
@ -240,6 +246,22 @@ The `op` (operations) currently supported in `kube-bench` are:
|
|||||||
- `regex`: tests if the flag value matches the compared value regular expression.
|
- `regex`: tests if the flag value matches the compared value regular expression.
|
||||||
When defining regular expressions in YAML it is generally easier to wrap them in
|
When defining regular expressions in YAML it is generally easier to wrap them in
|
||||||
single quotes, for example `'^[abc]$'`, to avoid issues with string escaping.
|
single quotes, for example `'^[abc]$'`, to avoid issues with string escaping.
|
||||||
|
- `bitmask` : tests if keyward is bitmasked with the compared value, common usege is for
|
||||||
|
comparing file permissions in linux.
|
||||||
|
|
||||||
|
## Omitting checks
|
||||||
|
|
||||||
|
If you decide that a recommendation is not appropriate for your environment, you can choose to omit it by editing the test YAML file to give it the check type `skip` as in this example:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
checks:
|
||||||
|
- id: 2.1.1
|
||||||
|
text: "Ensure that the --allow-privileged argument is set to false (Scored)"
|
||||||
|
type: "skip"
|
||||||
|
scored: true
|
||||||
|
```
|
||||||
|
|
||||||
|
No tests will be run for this check and the output will be marked [INFO].
|
||||||
|
|
||||||
## Configuration and Variables
|
## Configuration and Variables
|
||||||
|
|
||||||
@ -256,7 +278,7 @@ version-specific config overwrite similar values in `cfg/config.yaml`.
|
|||||||
For example, the kube-apiserver in Red Hat OCP distribution is run as
|
For example, the kube-apiserver in Red Hat OCP distribution is run as
|
||||||
`hypershift openshift-kube-apiserver` instead of the default `kube-apiserver`.
|
`hypershift openshift-kube-apiserver` instead of the default `kube-apiserver`.
|
||||||
This difference can be specified by editing the `master.apiserver.defaultbin`
|
This difference can be specified by editing the `master.apiserver.defaultbin`
|
||||||
entry `cfg/ocp-3.10/config.yaml`.
|
entry `cfg/rh-0.7/config.yaml`.
|
||||||
|
|
||||||
Below is the structure of `cfg/config.yaml`:
|
Below is the structure of `cfg/config.yaml`:
|
||||||
|
|
||||||
@ -283,7 +305,7 @@ Every node type has a subsection that specifies the main configuration items.
|
|||||||
Each component has the following entries:
|
Each component has the following entries:
|
||||||
|
|
||||||
- `bins`: A list of candidate binaries for a component. `kube-bench` checks this
|
- `bins`: A list of candidate binaries for a component. `kube-bench` checks this
|
||||||
list and selects the first binary that is running on the node.
|
list and selects the **first** binary that is running on the node.
|
||||||
|
|
||||||
If none of the binaries in `bins` list is running, `kube-bench` checks if the
|
If none of the binaries in `bins` list is running, `kube-bench` checks if the
|
||||||
binary specified by `defaultbin` is running and terminates if none of the
|
binary specified by `defaultbin` is running and terminates if none of the
|
||||||
@ -302,7 +324,7 @@ Every node type has a subsection that specifies the main configuration items.
|
|||||||
```
|
```
|
||||||
|
|
||||||
- `confs`: A list of candidate configuration files for a component. `kube-bench`
|
- `confs`: A list of candidate configuration files for a component. `kube-bench`
|
||||||
checks this list and selects the first config file that is found on the node.
|
checks this list and selects the **first** config file that is found on the node.
|
||||||
If none of the config files exists, `kube-bench` defaults conf to the value
|
If none of the config files exists, `kube-bench` defaults conf to the value
|
||||||
of `defaultconf`.
|
of `defaultconf`.
|
||||||
|
|
||||||
@ -319,7 +341,7 @@ Every node type has a subsection that specifies the main configuration items.
|
|||||||
```
|
```
|
||||||
|
|
||||||
- `svcs`: A list of candidate unitfiles for a component. `kube-bench` checks this
|
- `svcs`: A list of candidate unitfiles for a component. `kube-bench` checks this
|
||||||
list and selects the first unitfile that is found on the node. If none of the
|
list and selects the **first** unitfile that is found on the node. If none of the
|
||||||
unitfiles exists, `kube-bench` defaults unitfile to the value of `defaultsvc`.
|
unitfiles exists, `kube-bench` defaults unitfile to the value of `defaultsvc`.
|
||||||
|
|
||||||
The selected unitfile for a component can be referenced in `controls` via a
|
The selected unitfile for a component can be referenced in `controls` via a
|
||||||
@ -341,7 +363,7 @@ Every node type has a subsection that specifies the main configuration items.
|
|||||||
```
|
```
|
||||||
|
|
||||||
- `kubeconfig`: A list of candidate kubeconfig files for a component. `kube-bench`
|
- `kubeconfig`: A list of candidate kubeconfig files for a component. `kube-bench`
|
||||||
checks this list and selects the first file that is found on the node. If none
|
checks this list and selects the **first** file that is found on the node. If none
|
||||||
of the files exists, `kube-bench` defaults kubeconfig to the value of
|
of the files exists, `kube-bench` defaults kubeconfig to the value of
|
||||||
`defaultkubeconfig`.
|
`defaultkubeconfig`.
|
||||||
|
|
137
docs/flags-and-commands.md
Normal file
@ -0,0 +1,137 @@
|
|||||||
|
## Commands
|
||||||
|
Command | Description
|
||||||
|
--- | ---
|
||||||
|
help | Prints help about any command
|
||||||
|
run | List of components to run
|
||||||
|
version | Print kube-bench version
|
||||||
|
|
||||||
|
## Flags
|
||||||
|
Flag | Description
|
||||||
|
--- | ---
|
||||||
|
--alsologtostderr | log to standard error as well as files
|
||||||
|
--asff | Send findings to AWS Security Hub for any benchmark tests that fail or that generate a warning. See [this page][kube-bench-aws-security-hub] for more information on how to enable the kube-bench integration with AWS Security Hub.
|
||||||
|
--benchmark | Manually specify CIS benchmark version
|
||||||
|
-c, --check | A comma-delimited list of checks to run as specified in Benchmark document.
|
||||||
|
--config | config file (default is ./cfg/config.yaml)
|
||||||
|
--exit-code | Specify the exit code for when checks fail
|
||||||
|
--group | Run all the checks under this comma-delimited list of groups.
|
||||||
|
--include-test-output | Prints the actual result when test fails.
|
||||||
|
--json | Prints the results as JSON
|
||||||
|
--junit | Prints the results as JUnit
|
||||||
|
--log_backtrace_at traceLocation | when logging hits line file:N, emit a stack trace (default :0)
|
||||||
|
--logtostderr | log to standard error instead of files
|
||||||
|
--noremediations | Disable printing of remediations section to stdout.
|
||||||
|
--noresults | Disable printing of results section to stdout.
|
||||||
|
--nototals | Disable calculating and printing of totals for failed, passed, ... checks across all sections
|
||||||
|
--outputfile | Writes the JSON results to output file
|
||||||
|
--pgsql | Save the results to PostgreSQL
|
||||||
|
--scored | Run the scored CIS checks (default true)
|
||||||
|
--skip string | List of comma separated values of checks to be skipped
|
||||||
|
--stderrthreshold severity | logs at or above this threshold go to stderr (default 2)
|
||||||
|
-v, --v Level | log level for V logs (default 0)
|
||||||
|
--version string | Manually specify Kubernetes version, automatically detected if unset
|
||||||
|
--vmodule moduleSpec | comma-separated list of pattern=N settings for file-filtered logging
|
||||||
|
|
||||||
|
### Examples
|
||||||
|
|
||||||
|
#### Report kube-bench findings to AWS Security Hub
|
||||||
|
|
||||||
|
You can configure kube-bench with the `--asff` option to send findings to AWS Security Hub for any benchmark tests that fail or that generate a warning. See [this page](asff.md) for more information on how to enable the kube-bench integration with AWS Security Hub.
|
||||||
|
|
||||||
|
#### Specifying the benchmark or Kubernetes version
|
||||||
|
|
||||||
|
`kube-bench` uses the Kubernetes API, or access to the `kubectl` or `kubelet` executables to try to determine the Kubernetes version, and hence which benchmark to run. If you wish to override this, or if none of these methods are available, you can specify either the Kubernetes version or CIS Benchmark as a command line parameter.
|
||||||
|
|
||||||
|
You can specify a particular version of Kubernetes by setting the `--version` flag or with the `KUBE_BENCH_VERSION` environment variable. The value of `--version` takes precedence over the value of `KUBE_BENCH_VERSION`.
|
||||||
|
|
||||||
|
For example, run kube-bench using the tests for Kubernetes version 1.13:
|
||||||
|
|
||||||
|
```
|
||||||
|
kube-bench --version 1.13
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
You can specify `--benchmark` to run a specific CIS Benchmark version:
|
||||||
|
|
||||||
|
```
|
||||||
|
kube-bench --benchmark cis-1.5
|
||||||
|
```
|
||||||
|
|
||||||
|
**Note:** It is an error to specify both `--version` and `--benchmark` flags together
|
||||||
|
|
||||||
|
#### Specifying Benchmark sections
|
||||||
|
|
||||||
|
If you want to run specific CIS Benchmark sections (i.e master, node, etcd, etc...)
|
||||||
|
you can use the `run --targets` subcommand.
|
||||||
|
|
||||||
|
```
|
||||||
|
kube-bench run --targets master,node
|
||||||
|
```
|
||||||
|
|
||||||
|
or
|
||||||
|
|
||||||
|
```
|
||||||
|
kube-bench run --targets master,node,etcd,policies
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
If no targets are specified, `kube-bench` will determine the appropriate targets based on the CIS Benchmark version and the components detected on the node. The detection is done by verifying which components are running, as defined in the config files (see [Configuration](controls.md#configuration-and-variables).
|
||||||
|
|
||||||
|
#### Run specific check or group
|
||||||
|
|
||||||
|
`kube-bench` supports running individual checks by specifying the check's `id`
|
||||||
|
as a comma-delimited list on the command line with the `--check` | `-c` flag.
|
||||||
|
`kube-bench --check="1.1.1,1.1.2,1.2.1,1.3.3"`
|
||||||
|
|
||||||
|
`kube-bench` supports running all checks under group by specifying the group's `id`
|
||||||
|
as a comma-delimited list on the command line with the `--group` | `-g` flag.
|
||||||
|
`kube-bench --check="1.1,2.2"`
|
||||||
|
Will run all checks 1.1.X and 2.2.X.
|
||||||
|
|
||||||
|
#### Skip specific check or group
|
||||||
|
|
||||||
|
`kube-bench` supports skipping checks or groups by specifying the `id`
|
||||||
|
as a comma-delimited list on the command line with the `--skip` flag.
|
||||||
|
`kube-bench --skip="1.1,1.2.1,1.3.3"`
|
||||||
|
Will skip 1.1.X group and individual checks 1.2.1, 1.3.3.
|
||||||
|
Skipped checks returns [INFO] output.
|
||||||
|
|
||||||
|
#### Exit code
|
||||||
|
|
||||||
|
`kube-bench` supports using uniqe exit code when failing a check or more.
|
||||||
|
`kube-bench --exit-code 42`
|
||||||
|
Will return 42 if one check or more failed, and 0 incase none failed.
|
||||||
|
**Note:** [WARN] is not [FAIL].
|
||||||
|
|
||||||
|
#### Output manipulation flags
|
||||||
|
|
||||||
|
There are four output states:
|
||||||
|
- [PASS] indicates that the test was run successfully, and passed.
|
||||||
|
- [FAIL] indicates that the test was run successfully, and failed. The remediation output describes how to correct the configuration, or includes an error message describing why the test could not be run.
|
||||||
|
- [WARN] means this test needs further attention, for example it is a test that needs to be run manually. Check the remediation output for further information.
|
||||||
|
- [INFO] is informational output that needs no further action.
|
||||||
|
|
||||||
|
Note:
|
||||||
|
- If the test is Manual, this always generates WARN (because the user has to run it manually)
|
||||||
|
- If the test is Scored, and kube-bench was unable to run the test, this generates FAIL (because the test has not been passed, and as a Scored test, if it doesn't pass then it must be considered a failure).
|
||||||
|
- If the test is Not Scored, and kube-bench was unable to run the test, this generates WARN.
|
||||||
|
- If the test is Scored, type is empty, and there are no `test_items` present, it generates a WARN. This is to highlight tests that appear to be incompletely defined.
|
||||||
|
|
||||||
|
`kube-bench` supports multiple output manipulation flags.
|
||||||
|
`kube-bench --include-test-output` will print failing checks output in the results section
|
||||||
|
```
|
||||||
|
[INFO] 1 Master Node Security Configuration
|
||||||
|
[INFO] 1.1 Master Node Configuration Files
|
||||||
|
[FAIL] 1.1.1 Ensure that the API server pod specification file permissions are set to 644 or more restrictive (Automated)
|
||||||
|
**permissions=777**
|
||||||
|
```
|
||||||
|
|
||||||
|
**Note:** `--noresults` `--noremediations` and `--include-test-output` **will not** effect the json output but only stdout.
|
||||||
|
Only `--nototals` will effect the json output and thats because it will not call the function to calculate totals.
|
||||||
|
|
||||||
|
|
||||||
|
#### Troubleshooting
|
||||||
|
|
||||||
|
Running `kube-bench` with the `-v 3` parameter will generate debug logs that can be very helpful for debugging problems.
|
||||||
|
|
||||||
|
If you are using one of the example `job*.yaml` files, you will need to edit the `command` field, for example `["kube-bench", "-v", "3"]`. Once the job has run, the logs can be retrieved using `kubectl logs` on the job's pod.
|
Before Width: | Height: | Size: 85 KiB After Width: | Height: | Size: 85 KiB |
BIN
docs/images/kube-bench-logo-only.png
Normal file
After Width: | Height: | Size: 64 KiB |
Before Width: | Height: | Size: 124 KiB After Width: | Height: | Size: 124 KiB |
BIN
docs/images/kube-bench.jpg
Normal file
After Width: | Height: | Size: 58 KiB |
BIN
docs/images/kube-bench.png
Normal file
After Width: | Height: | Size: 86 KiB |
86
docs/images/kube-bench.svg
Normal file
@ -0,0 +1,86 @@
|
|||||||
|
<?xml version="1.0" encoding="iso-8859-1"?>
|
||||||
|
<!-- Generator: Adobe Illustrator 25.2.1, SVG Export Plug-In . SVG Version: 6.00 Build 0) -->
|
||||||
|
<svg version="1.1" id="_x30_1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" x="0px" y="0px"
|
||||||
|
width="500px" height="135px" viewBox="0 0 500 135" enable-background="new 0 0 500 135" xml:space="preserve">
|
||||||
|
<polygon fill="#1904DA" points="71.153,8.189 31.4,62.284 71.153,112.569 110.419,62.923 "/>
|
||||||
|
<path fill="#FF445F" d="M46.731,131.015c0.001,0,0.002,0,0.003,0l48.846-0.011c0.002,0,0.004,0,0.005,0
|
||||||
|
c1.14,0,2.273-0.246,3.319-0.694l-27.752-17.741l-27.598,17.813C44.561,130.792,45.643,131.015,46.731,131.015z"/>
|
||||||
|
<path fill="#FFC900" d="M110.419,62.923l-39.266,49.646l27.752,17.741c1.262-0.541,2.397-1.376,3.256-2.442l27.959-34.782
|
||||||
|
l2.489-3.097c0.513-0.638,0.923-1.354,1.224-2.112c0.143-0.359,0.261-0.728,0.353-1.103L110.419,62.923z"/>
|
||||||
|
<path fill="#FFC900" d="M8.078,86.64c0.217,0.956,0.599,1.875,1.137,2.697c0.149,0.229,0.309,0.45,0.478,0.664l30.461,37.873
|
||||||
|
c0.892,1.108,2.08,1.969,3.402,2.508l27.598-17.813L31.4,62.284L8.078,86.64z"/>
|
||||||
|
<path fill="#00FFE4" d="M20.78,32.099c-0.897,1.028-1.543,2.271-1.856,3.634L8.072,82.937c-0.242,1.052-0.266,2.15-0.089,3.214
|
||||||
|
c0.027,0.164,0.058,0.327,0.095,0.488L31.4,62.284L20.78,32.099z"/>
|
||||||
|
<path fill="#00FFE4" d="M134.188,86.774c0.311-1.258,0.34-2.585,0.049-3.848l-10.873-47.232c-0.295-1.279-0.884-2.452-1.7-3.438
|
||||||
|
l-11.244,30.667L134.188,86.774z"/>
|
||||||
|
<g>
|
||||||
|
<path fill="#08B1D5" d="M56.624,27.961L71.153,8.189c-0.004,0-0.008,0-0.013,0c-0.017,0-0.035,0.001-0.052,0.001
|
||||||
|
C70.964,8.191,70.84,8.194,70.715,8.2c-0.014,0.001-0.028,0.003-0.043,0.004c-1.1,0.06-2.188,0.337-3.182,0.812L23.483,30.043
|
||||||
|
c-1.046,0.5-1.96,1.204-2.703,2.056L31.4,62.284L56.624,27.95V27.961z"/>
|
||||||
|
<path fill="#08B1D5" d="M118.832,30.042L74.797,9.016c-1.132-0.542-2.387-0.825-3.643-0.827l39.266,54.733l11.244-30.667
|
||||||
|
C120.901,31.333,119.94,30.571,118.832,30.042z"/>
|
||||||
|
</g>
|
||||||
|
<g>
|
||||||
|
<path fill="#07242D" d="M179,108.611h-8.361l-16.315-16.496c-0.664,0.083-1.34,0.126-2.027,0.126v16.37h-5.959V62.369h5.959
|
||||||
|
c0,0-0.011,23.984,0,23.984c2.902,0,5.558-1.198,7.443-3.125l7.132-7.286h8.545l-11.596,11.514
|
||||||
|
c-1.027,1.028-2.192,1.921-3.462,2.646L179,108.611z"/>
|
||||||
|
<path fill="#07242D" d="M211.871,75.856v16.505c0,0,0,0.024,0,0.035c0,8.961-7.261,16.215-16.223,16.215
|
||||||
|
c-8.961,0-16.217-7.276-16.217-16.237c0-0.012,0-16.518,0-16.518h5.778v16.505c0,5.762,4.677,10.457,10.439,10.457
|
||||||
|
c5.762,0,10.433-4.695,10.433-10.457V75.856H211.871z"/>
|
||||||
|
<path fill="#07242D" d="M250.26,92.238c0,9.042-7.33,16.373-16.373,16.373c-3.967,0-7.605-1.411-10.438-3.758v3.758h-5.944
|
||||||
|
c0.004-0.373,0.004-46.242,0.004-46.242h5.944l-0.003,17.254c2.834-2.348,6.471-3.758,10.439-3.758
|
||||||
|
C242.93,75.864,250.261,83.195,250.26,92.238z M244.333,92.238c0-5.769-4.677-10.445-10.446-10.445
|
||||||
|
c-5.637,0-10.447,4.578-10.447,10.429c0,5.851,4.81,10.462,10.447,10.462C239.656,102.683,244.333,98.007,244.333,92.238z"/>
|
||||||
|
<path fill="#07242D" d="M286.212,94.367h-26.414c0.994,4.714,5.176,8.271,10.181,8.271c3.265,0,6.176-1.516,8.081-3.878h6.927
|
||||||
|
c-2.529,5.792-8.3,9.851-15.007,9.851c-9.033,0-16.379-7.358-16.379-16.402s7.345-16.353,16.379-16.353
|
||||||
|
C279.783,75.779,287.568,84.659,286.212,94.367z M279.65,88.392c-1.521-3.845-5.277-6.553-9.672-6.553s-8.155,2.71-9.679,6.553
|
||||||
|
H279.65z"/>
|
||||||
|
<path fill="#07242D" d="M307.437,86.979v5.459h-16.855v-5.459H307.437z"/>
|
||||||
|
<path fill="#07242D" d="M345.923,92.238c0,9.042-7.33,16.373-16.373,16.373c-3.967,0-7.605-1.411-10.438-3.758v3.758h-5.944
|
||||||
|
c0.004-0.373,0.004-46.242,0.004-46.242h5.944l-0.003,17.254c2.834-2.348,6.471-3.758,10.438-3.758
|
||||||
|
C338.593,75.864,345.924,83.195,345.923,92.238z M339.996,92.238c0-5.769-4.677-10.445-10.446-10.445
|
||||||
|
c-5.637,0-10.447,4.578-10.447,10.429c0,5.851,4.81,10.462,10.447,10.462C335.318,102.683,339.996,98.007,339.996,92.238z"/>
|
||||||
|
<path fill="#07242D" d="M381.874,94.367H355.46c0.994,4.714,5.176,8.271,10.181,8.271c3.265,0,6.176-1.516,8.081-3.878h6.927
|
||||||
|
c-2.529,5.792-8.3,9.851-15.007,9.851c-9.033,0-16.379-7.358-16.379-16.402s7.345-16.353,16.379-16.353
|
||||||
|
C375.445,75.779,383.23,84.659,381.874,94.367z M375.312,88.392c-1.521-3.845-5.277-6.553-9.672-6.553s-8.155,2.71-9.679,6.553
|
||||||
|
H375.312z"/>
|
||||||
|
<path fill="#07242D" d="M419.609,92.201c0,11.479,0,16.41,0,16.41h-5.976c0,0,0-10.761,0-16.41c0-5.855-4.767-10.363-10.389-10.363
|
||||||
|
c-5.622,0-10.41,4.458-10.41,10.363c0,5.652,0,16.41,0,16.41h-5.975V75.856c0,0,2.56,0,5.975,0v3.69c0,0,3.921-3.69,10.41-3.69
|
||||||
|
C410.942,75.856,419.609,81.839,419.609,92.201z"/>
|
||||||
|
<path fill="#07242D" d="M447.468,99.621l4.194,4.194c-2.964,2.964-7.058,4.797-11.581,4.797c-4.522,0-8.616-1.833-11.581-4.797
|
||||||
|
c-2.964-2.964-4.797-7.058-4.797-11.581s1.833-8.616,4.797-11.581c2.964-2.964,7.058-4.797,11.581-4.797
|
||||||
|
c4.522,0,8.616,1.833,11.581,4.797l-4.194,4.194c-1.89-1.891-4.502-3.061-7.386-3.061s-5.497,1.17-7.386,3.061
|
||||||
|
c-1.891,1.89-3.06,4.502-3.06,7.386c0,2.885,1.169,5.497,3.06,7.387c1.89,1.89,4.502,3.059,7.386,3.059
|
||||||
|
S445.577,101.511,447.468,99.621z"/>
|
||||||
|
<path fill="#07242D" d="M488.639,92.244c0,11.448,0,16.366,0,16.366h-5.96c0,0,0-10.733,0-16.366
|
||||||
|
c0-5.838-4.756-10.334-10.361-10.334c-5.607,0-10.382,4.446-10.382,10.334c0,5.637,0,16.366,0,16.366h-5.958v-46.24h5.958v17.255
|
||||||
|
c0,0,3.909-3.679,10.382-3.679C479.996,75.945,488.639,81.912,488.639,92.244z"/>
|
||||||
|
</g>
|
||||||
|
<g>
|
||||||
|
<path fill="#07242D" d="M180.326,58.699h3.129V39.263c0.01-0.171,0-0.344,0-0.517c0-4.751-3.841-8.602-8.592-8.602
|
||||||
|
c-4.751,0-8.602,3.851-8.602,8.602s3.851,8.602,8.602,8.602h0.435l3.164-3.15h-3.36h-0.239c-3.011,0-5.451-2.441-5.451-5.451
|
||||||
|
s2.441-5.451,5.451-5.451c3.011,0,5.463,2.441,5.463,5.451V58.699z"/>
|
||||||
|
<g>
|
||||||
|
<path fill="#07242D" d="M200.111,30.144v8.709c0,3.041-2.465,5.518-5.505,5.518c-3.041,0-5.508-2.477-5.508-5.518v-8.709h-3.049
|
||||||
|
v8.709c0,0,0,0,0,0.007c0,4.729,3.828,8.568,8.557,8.568c4.729,0,8.561-3.827,8.561-8.556c0-0.006,0-0.019,0-0.019v-8.709H200.111
|
||||||
|
z"/>
|
||||||
|
</g>
|
||||||
|
<g>
|
||||||
|
<path fill="#07242D" d="M163.154,35.833c-3.405-8.994-16.602-6.81-16.802,2.939c0.005,2.094,0.724,3.972,1.979,5.502
|
||||||
|
c1.472,1.787,3.646,2.973,6.101,3.134c0.189,0.012,0.379,0.019,0.57,0.019h8.665c0,0,0-8.656,0-8.655
|
||||||
|
C163.666,37.773,163.493,36.772,163.154,35.833z M160.464,44.267c0,0-3.937,0-5.455,0c-3.028,0-5.482-2.468-5.482-5.496
|
||||||
|
c0-1.517,0.617-2.877,1.613-3.87l0.001,0.001c3.386-3.431,9.345-1.024,9.324,3.869C160.464,40.289,160.464,44.267,160.464,44.267z
|
||||||
|
"/>
|
||||||
|
</g>
|
||||||
|
<g>
|
||||||
|
<path fill="#07242D" d="M222.563,35.833c-3.405-8.994-16.602-6.81-16.802,2.939c0.005,2.094,0.724,3.972,1.979,5.502
|
||||||
|
c1.472,1.787,3.646,2.973,6.101,3.134c0.189,0.012,0.379,0.019,0.57,0.019h8.665c0,0,0-8.656,0-8.655
|
||||||
|
C223.075,37.773,222.902,36.772,222.563,35.833z M219.873,44.267c0,0-3.938,0-5.455,0c-3.028,0-5.482-2.468-5.482-5.496
|
||||||
|
c0-1.517,0.617-2.877,1.613-3.87l0.001,0.001c3.386-3.431,9.345-1.024,9.324,3.869C219.873,40.289,219.873,44.267,219.873,44.267z
|
||||||
|
"/>
|
||||||
|
</g>
|
||||||
|
</g>
|
||||||
|
<path fill="#FFFFFF" d="M87.645,83.488h-8.361L62.969,66.992c-0.664,0.083-1.34,0.126-2.027,0.126v16.37h-5.959V37.246h5.959
|
||||||
|
c0,0-0.011,23.984,0,23.984c2.902,0,5.558-1.198,7.443-3.125l7.132-7.286h8.545L72.467,62.333c-1.027,1.028-2.192,1.921-3.462,2.646
|
||||||
|
L87.645,83.488z"/>
|
||||||
|
</svg>
|
After Width: | Height: | Size: 7.0 KiB |
Before Width: | Height: | Size: 136 KiB After Width: | Height: | Size: 136 KiB |
35
docs/index.md
Normal file
@ -0,0 +1,35 @@
|
|||||||
|
[download]: https://img.shields.io/github/downloads/aquasecurity/kube-bench/total?logo=github
|
||||||
|
[release-img]: https://img.shields.io/github/release/aquasecurity/kube-bench.svg?logo=github
|
||||||
|
[release]: https://github.com/aquasecurity/kube-bench/releases
|
||||||
|
[docker-pull]: https://img.shields.io/docker/pulls/aquasec/kube-bench?logo=docker&label=docker%20pulls%20%2F%20kube-bench
|
||||||
|
[cov-img]: https://codecov.io/github/aquasecurity/kube-bench/branch/main/graph/badge.svg
|
||||||
|
[cov]: https://codecov.io/github/aquasecurity/kube-bench
|
||||||
|
[report-card-img]: https://goreportcard.com/badge/github.com/aquasecurity/kube-bench
|
||||||
|
[report-card]: https://goreportcard.com/report/github.com/aquasecurity/kube-bench
|
||||||
|
|
||||||
|
![Kube-bench Logo](images/kube-bench.jpg)
|
||||||
|
[![GitHub Release][release-img]][release]
|
||||||
|
![Downloads][download]
|
||||||
|
![Docker Pulls][docker-pull]
|
||||||
|
[![Go Report Card][report-card-img]][report-card]
|
||||||
|
[![Build Status](https://github.com/aquasecurity/kube-bench/workflows/Build/badge.svg?branch=main)](https://github.com/aquasecurity/kube-bench/actions)
|
||||||
|
[![License](https://img.shields.io/badge/License-Apache%202.0-blue.svg)](https://github.com/aquasecurity/kube-bench/blob/main/LICENSE)
|
||||||
|
[![Docker image](https://images.microbadger.com/badges/image/aquasec/kube-bench.svg)](https://microbadger.com/images/aquasec/kube-bench "Get your own image badge on microbadger.com")
|
||||||
|
[![Source commit](https://images.microbadger.com/badges/commit/aquasec/kube-bench.svg)](https://microbadger.com/images/aquasec/kube-bench)
|
||||||
|
[![Coverage Status][cov-img]][cov]
|
||||||
|
|
||||||
|
|
||||||
|
# Kube-bench
|
||||||
|
|
||||||
|
kube-bench is a Go application that checks whether Kubernetes is deployed securely by running the checks documented in the [CIS Kubernetes Benchmark](https://www.cisecurity.org/benchmark/kubernetes/).
|
||||||
|
|
||||||
|
Tests are configured with YAML files, making this tool easy to update as test specifications evolve.
|
||||||
|
|
||||||
|
|
||||||
|
1. kube-bench implements the [CIS Kubernetes Benchmark](https://www.cisecurity.org/benchmark/kubernetes/) as closely as possible. Please raise issues here if kube-bench is not correctly implementing the test as described in the Benchmark. To report issues in the Benchmark itself (for example, tests that you believe are inappropriate), please join the [CIS community](https://cisecurity.org).
|
||||||
|
|
||||||
|
1. There is not a one-to-one mapping between releases of Kubernetes and releases of the CIS benchmark. See [CIS Kubernetes Benchmark support](#cis-kubernetes-benchmark-support) to see which releases of Kubernetes are covered by different releases of the benchmark.
|
||||||
|
|
||||||
|
1. It is impossible to inspect the master nodes of managed clusters, e.g. GKE, EKS, AKS and ACK, using kube-bench as one does not have access to such nodes, although it is still possible to use kube-bench to check worker node configuration in these environments.
|
||||||
|
|
||||||
|
For help and more information go to our [github discussions q&a](https://github.com/aquasecurity/kube-bench/discussions/categories/q-a)
|
79
docs/installation.md
Normal file
@ -0,0 +1,79 @@
|
|||||||
|
## Installation
|
||||||
|
|
||||||
|
You can choose to
|
||||||
|
* Run kube-bench from inside a container (sharing PID namespace with the host). See [Running inside a container](./running.md#running-inside-a-container) for additional details.
|
||||||
|
* Run a container that installs kube-bench on the host, and then run kube-bench directly on the host. See [Installing from a container](#installing-from-a-container) for additional details.
|
||||||
|
* install the latest binaries from the [Releases page](https://github.com/aquasecurity/kube-bench/releases), though please note that you also need to download the config and test files from the `cfg` directory. See [Download and Install binaries](#download-and-install-binaries) for details.
|
||||||
|
* Compile it from source. See [Installing from sources](#installing-from-sources) for details.
|
||||||
|
|
||||||
|
|
||||||
|
### Download and Install binaries
|
||||||
|
|
||||||
|
It is possible to manually install and run kube-bench release binaries. In order to do that, you must have access to your Kubernetes cluster nodes. Note that if you're using one of the managed Kubernetes services (e.g. EKS, AKS, GKE, ACK, OCP), you will not have access to the master nodes of your cluster and you can’t perform any tests on the master nodes.
|
||||||
|
|
||||||
|
First, log into one of the nodes using SSH.
|
||||||
|
|
||||||
|
Install kube-bench binary for your platform using the commands below. Note that there may be newer releases available. See [releases page](https://github.com/aquasecurity/kube-bench/releases).
|
||||||
|
|
||||||
|
Ubuntu/Debian:
|
||||||
|
|
||||||
|
```
|
||||||
|
curl -L https://github.com/aquasecurity/kube-bench/releases/download/v0.6.2/kube-bench_0.6.2_linux_amd64.deb -o kube-bench_0.6.2_linux_amd64.deb
|
||||||
|
|
||||||
|
sudo apt install ./kube-bench_0.6.2_linux_amd64.deb -f
|
||||||
|
```
|
||||||
|
|
||||||
|
RHEL:
|
||||||
|
|
||||||
|
```
|
||||||
|
curl -L https://github.com/aquasecurity/kube-bench/releases/download/v0.6.2/kube-bench_0.6.2_linux_amd64.rpm -o kube-bench_0.6.2_linux_amd64.rpm
|
||||||
|
|
||||||
|
sudo yum install kube-bench_0.6.2_linux_amd64.rpm -y
|
||||||
|
```
|
||||||
|
|
||||||
|
Alternatively, you can manually download and extract the kube-bench binary:
|
||||||
|
|
||||||
|
```
|
||||||
|
curl -L https://github.com/aquasecurity/kube-bench/releases/download/v0.6.2/kube-bench_0.6.2_linux_amd64.tar.gz -o kube-bench_0.6.2_linux_amd64.tar.gz
|
||||||
|
|
||||||
|
tar -xvf kube-bench_0.6.2_linux_amd64.tar.gz
|
||||||
|
```
|
||||||
|
|
||||||
|
You can then run kube-bench directly:
|
||||||
|
```
|
||||||
|
kube-bench
|
||||||
|
```
|
||||||
|
|
||||||
|
If you manually downloaded the kube-bench binary (using curl command above), you have to specify the location of configuration directory and file. For example:
|
||||||
|
```
|
||||||
|
./kube-bench --config-dir `pwd`/cfg --config `pwd`/cfg/config.yaml
|
||||||
|
```
|
||||||
|
|
||||||
|
See previous section on [Running kube-bench](./running.md#running-kube-bench) for further details on using the kube-bench binary.
|
||||||
|
|
||||||
|
### Installing from sources
|
||||||
|
|
||||||
|
If Go is installed on the target machines, you can simply clone this repository and run as follows (assuming your [`GOPATH` is set](https://github.com/golang/go/wiki/GOPATH)):
|
||||||
|
|
||||||
|
```shell
|
||||||
|
go get github.com/aquasecurity/kube-bench
|
||||||
|
cd $GOPATH/src/github.com/aquasecurity/kube-bench
|
||||||
|
go build -o kube-bench .
|
||||||
|
|
||||||
|
# See all supported options
|
||||||
|
./kube-bench --help
|
||||||
|
|
||||||
|
# Run all checks
|
||||||
|
./kube-bench
|
||||||
|
```
|
||||||
|
|
||||||
|
|
||||||
|
### Installing from a container
|
||||||
|
|
||||||
|
This command copies the kube-bench binary and configuration files to your host from the Docker container:
|
||||||
|
**binaries compiled for linux-x86-64 only (so they won't run on macOS or Windows)**
|
||||||
|
```
|
||||||
|
docker run --rm -v `pwd`:/host aquasec/kube-bench:latest install
|
||||||
|
```
|
||||||
|
|
||||||
|
You can then run `./kube-bench`.
|
16
docs/platforms.md
Normal file
@ -0,0 +1,16 @@
|
|||||||
|
|
||||||
|
## CIS Kubernetes Benchmark support
|
||||||
|
|
||||||
|
kube-bench supports running tests for Kubernetes.
|
||||||
|
Most of our supported benchmarks are defined in the [CIS Kubernetes Benchmarks](https://www.cisecurity.org/benchmark/kubernetes/).
|
||||||
|
Some defined by other hardenening guides.
|
||||||
|
|
||||||
|
| Source | Kubernetes Benchmark | kube-bench config | Kubernetes versions |
|
||||||
|
|---|---|---|---|
|
||||||
|
| CIS | [1.5.1](https://workbench.cisecurity.org/benchmarks/4892) | cis-1.5 | 1.15- |
|
||||||
|
| CIS | [1.6.0](https://workbench.cisecurity.org/benchmarks/4834) | cis-1.6 | 1.16- |
|
||||||
|
| CIS | [GKE 1.0.0](https://workbench.cisecurity.org/benchmarks/4536) | gke-1.0 | GKE |
|
||||||
|
| CIS | [EKS 1.0.0](https://workbench.cisecurity.org/benchmarks/5190) | eks-1.0 | EKS |
|
||||||
|
| CIS | [ACK 1.0.0](https://workbench.cisecurity.org/benchmarks/6467) | ack-1.0 | ACK |
|
||||||
|
| RHEL | RedHat OpenShift hardening guide | rh-0.7 | OCP 3.10-3.11 |
|
||||||
|
| CIS | [OCP4 1.1.0](https://workbench.cisecurity.org/benchmarks/6778) | rh-1.0 | OCP 4.1- |
|
145
docs/running.md
Normal file
@ -0,0 +1,145 @@
|
|||||||
|
|
||||||
|
## Running kube-bench
|
||||||
|
|
||||||
|
If you run kube-bench directly from the command line you may need to be root / sudo to have access to all the config files.
|
||||||
|
|
||||||
|
By default kube-bench attempts to auto-detect the running version of Kubernetes, and map this to the corresponding CIS Benchmark version. For example, Kubernetes version 1.15 is mapped to CIS Benchmark version `cis-1.15` which is the benchmark version valid for Kubernetes 1.15.
|
||||||
|
|
||||||
|
kube-bench also attempts to identify the components running on the node, and uses this to determine which tests to run (for example, only running the master node tests if the node is running an API server).
|
||||||
|
|
||||||
|
**Please note**
|
||||||
|
It is impossible to inspect the master nodes of managed clusters, e.g. GKE, EKS, AKS and ACK, using kube-bench as one does not have access to such nodes, although it is still possible to use kube-bench to check worker node configuration in these environments.
|
||||||
|
|
||||||
|
### Running inside a container
|
||||||
|
|
||||||
|
You can avoid installing kube-bench on the host by running it inside a container using the host PID namespace and mounting the `/etc` and `/var` directories where the configuration and other files are located on the host so that kube-bench can check their existence and permissions.
|
||||||
|
|
||||||
|
```
|
||||||
|
docker run --pid=host -v /etc:/etc:ro -v /var:/var:ro -t aquasec/kube-bench:latest --version 1.18
|
||||||
|
```
|
||||||
|
|
||||||
|
> Note: the tests require either the kubelet or kubectl binary in the path in order to auto-detect the Kubernetes version. You can pass `-v $(which kubectl):/usr/local/mount-from-host/bin/kubectl` to resolve this. You will also need to pass in kubeconfig credentials. For example:
|
||||||
|
|
||||||
|
```
|
||||||
|
docker run --pid=host -v /etc:/etc:ro -v /var:/var:ro -v $(which kubectl):/usr/local/mount-from-host/bin/kubectl -v ~/.kube:/.kube -e KUBECONFIG=/.kube/config -t aquasec/kube-bench:latest
|
||||||
|
```
|
||||||
|
|
||||||
|
You can use your own configs by mounting them over the default ones in `/opt/kube-bench/cfg/`
|
||||||
|
|
||||||
|
```
|
||||||
|
docker run --pid=host -v /etc:/etc:ro -v /var:/var:ro -t -v path/to/my-config.yaml:/opt/kube-bench/cfg/config.yaml -v $(which kubectl):/usr/local/mount-from-host/bin/kubectl -v ~/.kube:/.kube -e KUBECONFIG=/.kube/config aquasec/kube-bench:latest
|
||||||
|
```
|
||||||
|
|
||||||
|
### Running in a Kubernetes cluster
|
||||||
|
|
||||||
|
You can run kube-bench inside a pod, but it will need access to the host's PID namespace in order to check the running processes, as well as access to some directories on the host where config files and other files are stored.
|
||||||
|
|
||||||
|
The supplied `job.yaml` file can be applied to run the tests as a job. For example:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
$ kubectl apply -f job.yaml
|
||||||
|
job.batch/kube-bench created
|
||||||
|
|
||||||
|
$ kubectl get pods
|
||||||
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
kube-bench-j76s9 0/1 ContainerCreating 0 3s
|
||||||
|
|
||||||
|
# Wait for a few seconds for the job to complete
|
||||||
|
$ kubectl get pods
|
||||||
|
NAME READY STATUS RESTARTS AGE
|
||||||
|
kube-bench-j76s9 0/1 Completed 0 11s
|
||||||
|
|
||||||
|
# The results are held in the pod's logs
|
||||||
|
kubectl logs kube-bench-j76s9
|
||||||
|
[INFO] 1 Master Node Security Configuration
|
||||||
|
[INFO] 1.1 API Server
|
||||||
|
...
|
||||||
|
```
|
||||||
|
|
||||||
|
To run tests on the master node, the pod needs to be scheduled on that node. This involves setting a nodeSelector and tolerations in the pod spec.
|
||||||
|
|
||||||
|
The default labels applied to master nodes has changed since Kubernetes 1.11, so if you are using an older version you may need to modify the nodeSelector and tolerations to run the job on the master node.
|
||||||
|
### Running in an AKS cluster
|
||||||
|
|
||||||
|
1. Create an AKS cluster(e.g. 1.13.7) with RBAC enabled, otherwise there would be 4 failures
|
||||||
|
|
||||||
|
1. Use the [kubectl-enter plugin](https://github.com/kvaps/kubectl-enter) to shell into a node
|
||||||
|
`
|
||||||
|
kubectl-enter {node-name}
|
||||||
|
`
|
||||||
|
or ssh to one agent node
|
||||||
|
could open nsg 22 port and assign a public ip for one agent node (only for testing purpose)
|
||||||
|
|
||||||
|
1. Run CIS benchmark to view results:
|
||||||
|
```
|
||||||
|
docker run --rm -v `pwd`:/host aquasec/kube-bench:latest install
|
||||||
|
./kube-bench
|
||||||
|
```
|
||||||
|
kube-bench cannot be run on AKS master nodes
|
||||||
|
|
||||||
|
### Running in an EKS cluster
|
||||||
|
|
||||||
|
There is a `job-eks.yaml` file for running the kube-bench node checks on an EKS cluster. The significant difference on EKS is that it's not possible to schedule jobs onto the master node, so master checks can't be performed
|
||||||
|
|
||||||
|
1. To create an EKS Cluster refer to [Getting Started with Amazon EKS](https://docs.aws.amazon.com/eks/latest/userguide/getting-started.html) in the *Amazon EKS User Guide*
|
||||||
|
- Information on configuring `eksctl`, `kubectl` and the AWS CLI is within
|
||||||
|
2. Create an [Amazon Elastic Container Registry (ECR)](https://docs.aws.amazon.com/AmazonECR/latest/userguide/what-is-ecr.html) repository to host the kube-bench container image
|
||||||
|
```
|
||||||
|
aws ecr create-repository --repository-name k8s/kube-bench --image-tag-mutability MUTABLE
|
||||||
|
```
|
||||||
|
3. Download, build and push the kube-bench container image to your ECR repo
|
||||||
|
```
|
||||||
|
git clone https://github.com/aquasecurity/kube-bench.git
|
||||||
|
cd kube-bench
|
||||||
|
aws ecr get-login-password --region <AWS_REGION> | docker login --username AWS --password-stdin <AWS_ACCT_NUMBER>.dkr.ecr.<AWS_REGION>.amazonaws.com
|
||||||
|
docker build -t k8s/kube-bench .
|
||||||
|
docker tag k8s/kube-bench:latest <AWS_ACCT_NUMBER>.dkr.ecr.<AWS_REGION>.amazonaws.com/k8s/kube-bench:latest
|
||||||
|
docker push <AWS_ACCT_NUMBER>.dkr.ecr.<AWS_REGION>.amazonaws.com/k8s/kube-bench:latest
|
||||||
|
```
|
||||||
|
4. Copy the URI of your pushed image, the URI format is like this: `<AWS_ACCT_NUMBER>.dkr.ecr.<AWS_REGION>.amazonaws.com/k8s/kube-bench:latest`
|
||||||
|
5. Replace the `image` value in `job-eks.yaml` with the URI from Step 4
|
||||||
|
6. Run the kube-bench job on a Pod in your Cluster: `kubectl apply -f job-eks.yaml`
|
||||||
|
7. Find the Pod that was created, it *should* be in the `default` namespace: `kubectl get pods --all-namespaces`
|
||||||
|
8. Retrieve the value of this Pod and output the report, note the Pod name will vary: `kubectl logs kube-bench-<value>`
|
||||||
|
- You can save the report for later reference: `kubectl logs kube-bench-<value> > kube-bench-report.txt`
|
||||||
|
|
||||||
|
|
||||||
|
### Running on OpenShift
|
||||||
|
|
||||||
|
| OpenShift Hardening Guide | kube-bench config |
|
||||||
|
|---|---|
|
||||||
|
| ocp-3.10 +| rh-0.7 |
|
||||||
|
| ocp-4.1 +| rh-1.0 |
|
||||||
|
|
||||||
|
kube-bench includes a set of test files for Red Hat's OpenShift hardening guide for OCP 3.10 and 4.1. To run this you will need to specify `--benchmark rh-07`, or `--version ocp-3.10` or,`--version ocp-4.5` or `--benchmark rh-1.0`
|
||||||
|
|
||||||
|
`kube-bench` supports auto-detection, when you run the `kube-bench` command it will autodetect if running in openshift environment.
|
||||||
|
|
||||||
|
### Running in a GKE cluster
|
||||||
|
|
||||||
|
| CIS Benchmark | Targets |
|
||||||
|
|---|---|
|
||||||
|
| gke-1.0| master, controlplane, node, etcd, policies, managedservices |
|
||||||
|
|
||||||
|
kube-bench includes benchmarks for GKE. To run this you will need to specify `--benchmark gke-1.0` when you run the `kube-bench` command.
|
||||||
|
|
||||||
|
To run the benchmark as a job in your GKE cluster apply the included `job-gke.yaml`.
|
||||||
|
|
||||||
|
```
|
||||||
|
kubectl apply -f job-gke.yaml
|
||||||
|
```
|
||||||
|
|
||||||
|
### Running in a ACK cluster
|
||||||
|
|
||||||
|
| CIS Benchmark | Targets |
|
||||||
|
|---|---|
|
||||||
|
| ack-1.0| master, controlplane, node, etcd, policies, managedservices |
|
||||||
|
|
||||||
|
kube-bench includes benchmarks for Alibaba Cloud Container Service For Kubernetes (ACK).
|
||||||
|
To run this you will need to specify `--benchmark ack-1.0` when you run the `kube-bench` command.
|
||||||
|
|
||||||
|
To run the benchmark as a job in your ACK cluster apply the included `job-ack.yaml`.
|
||||||
|
|
||||||
|
```
|
||||||
|
kubectl apply -f job-ack.yaml
|
||||||
|
```
|
Before Width: | Height: | Size: 17 KiB |
@ -1,121 +0,0 @@
|
|||||||
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
|
|
||||||
<svg
|
|
||||||
xmlns:dc="http://purl.org/dc/elements/1.1/"
|
|
||||||
xmlns:cc="http://creativecommons.org/ns#"
|
|
||||||
xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
|
|
||||||
xmlns:svg="http://www.w3.org/2000/svg"
|
|
||||||
xmlns="http://www.w3.org/2000/svg"
|
|
||||||
viewBox="0 0 831.49597 755.90533"
|
|
||||||
height="755.90533"
|
|
||||||
width="831.49597"
|
|
||||||
xml:space="preserve"
|
|
||||||
id="svg2"
|
|
||||||
version="1.1"><metadata
|
|
||||||
id="metadata8"><rdf:RDF><cc:Work
|
|
||||||
rdf:about=""><dc:format>image/svg+xml</dc:format><dc:type
|
|
||||||
rdf:resource="http://purl.org/dc/dcmitype/StillImage" /></cc:Work></rdf:RDF></metadata><defs
|
|
||||||
id="defs6"><clipPath
|
|
||||||
id="clipPath22"
|
|
||||||
clipPathUnits="userSpaceOnUse"><path
|
|
||||||
id="path20"
|
|
||||||
d="M 0,566.929 H 623.622 V 0 H 0 Z" /></clipPath></defs><g
|
|
||||||
transform="matrix(1.3333333,0,0,-1.3333333,0,755.90533)"
|
|
||||||
id="g10"><g
|
|
||||||
transform="translate(314.8111,521.959)"
|
|
||||||
id="g12"><path
|
|
||||||
id="path14"
|
|
||||||
style="fill:#0ab1d5;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="M 0,0 -106.784,-145.31 0,-280.384 105.477,-147.025 Z" /></g><g
|
|
||||||
id="g16"><g
|
|
||||||
clip-path="url(#clipPath22)"
|
|
||||||
id="g18"><g
|
|
||||||
transform="translate(51.8912,72.061)"
|
|
||||||
id="g24"><path
|
|
||||||
id="path26"
|
|
||||||
style="fill:#464648;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="m 0,0 v 71.061 c 0,3.629 2.86,6.6 6.6,6.6 3.74,0 6.6,-2.971 6.6,-6.6 V 32.45 h 2.97 c 1.32,0 2.42,0.551 3.52,1.981 L 33.44,52.69 c 1.43,1.981 3.081,3.3 5.72,3.3 3.63,0 6.271,-2.969 6.271,-6.599 0,-1.87 -0.881,-3.411 -1.981,-4.731 L 29.59,27.5 44.44,3.96 C 45.32,2.641 45.76,1.21 45.76,0 c 0,-3.63 -2.97,-6.6 -6.6,-6.6 -2.309,0 -4.4,1.54 -5.5,3.411 L 19.8,19.25 c -0.88,1.431 -1.98,2.091 -3.52,2.091 H 13.2 L 13.2,0 C 13.2,-3.63 10.34,-6.6 6.6,-6.6 2.86,-6.6 0,-3.63 0,0" /></g><g
|
|
||||||
transform="translate(104.9547,86.8013)"
|
|
||||||
id="g28"><path
|
|
||||||
id="path30"
|
|
||||||
style="fill:#464648;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="m 0,0 v 34.65 c 0,3.63 2.97,6.6 6.6,6.6 3.629,0 6.6,-2.97 6.6,-6.6 V 2.86 c 0,-8.47 3.409,-11.44 9.57,-11.44 4.73,0 9.24,2.86 11.33,4.95 v 38.28 c 0,3.63 2.97,6.6 6.6,6.6 3.63,0 6.6,-2.97 6.6,-6.6 v -50.16 c 0,-3.3 -2.53,-5.83 -5.72,-5.83 -2.97,0 -5.06,2.09 -5.72,4.95 l -0.55,2.42 C 32.12,-17.16 26.18,-21.34 18.149,-21.34 5.06,-21.34 0,-11.99 0,0" /></g><g
|
|
||||||
transform="translate(197.5084,90.4312)"
|
|
||||||
id="g32"><path
|
|
||||||
id="path34"
|
|
||||||
style="fill:#464648;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="m 0,0 v 12.65 c 0,8.47 -2.971,12.54 -10.341,12.54 -4.069,0 -8.029,-2.2 -10.559,-4.839 V -7.59 c 2.53,-2.639 6.49,-4.95 10.559,-4.95 C -2.971,-12.54 0,-8.47 0,0 m -34.101,-19.14 v 71.83 c 0,3.63 2.861,6.601 6.6,6.601 3.74,0 6.601,-2.971 6.601,-6.601 V 31.57 c 3.08,3.191 8.359,6.05 14.299,6.05 13.09,0 19.8,-8.8 19.8,-23.54 V -1.319 c 0,-14.741 -6.819,-23.651 -20.13,-23.651 -6.16,0 -11.88,2.97 -14.96,6.491 l -0.66,-2.201 c -0.769,-2.53 -3.08,-4.29 -5.72,-4.29 -3.299,0 -5.83,2.75 -5.83,5.83" /></g><g
|
|
||||||
transform="translate(251.7047,102.311)"
|
|
||||||
id="g36"><path
|
|
||||||
id="path38"
|
|
||||||
style="fill:#464648;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="m 0,0 c 0,9.57 -1.87,14.301 -9.9,14.301 -7.92,0 -9.9,-4.181 -9.9,-14.301 z M -33,-15.069 V 2.2 c 0,14.521 7.479,23.54 23.1,23.54 15.95,0 22.77,-8.689 22.77,-23.54 v -7.37 c 0,-2.859 -2.309,-5.17 -5.17,-5.17 h -27.5 v -5.939 c 0,-4.62 2.86,-9.13 10.89,-9.13 5.72,0 8.8,0.88 13.09,2.97 0.66,0.33 1.54,0.66 2.42,0.66 2.97,0 5.39,-2.42 5.39,-5.391 0,-2.309 -1.429,-3.96 -3.52,-5.17 -5.17,-2.97 -10.23,-4.51 -17.93,-4.51 -15.73,0 -23.54,8.25 -23.54,21.781" /></g><g
|
|
||||||
transform="translate(271.7564,99.4517)"
|
|
||||||
id="g40"><path
|
|
||||||
id="path42"
|
|
||||||
style="fill:#464648;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="m 0,0 c 0,3.3 2.53,5.83 5.721,5.83 h 19.91 c 3.3,0 5.83,-2.53 5.83,-5.83 0,-3.19 -2.53,-5.72 -5.83,-5.72 H 5.721 C 2.53,-5.72 0,-3.19 0,0" /></g><g
|
|
||||||
transform="translate(345.776,90.4312)"
|
|
||||||
id="g44"><path
|
|
||||||
id="path46"
|
|
||||||
style="fill:#464648;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="m 0,0 v 12.65 c 0,8.47 -2.971,12.54 -10.341,12.54 -4.069,0 -8.029,-2.2 -10.559,-4.839 V -7.59 c 2.53,-2.639 6.49,-4.95 10.559,-4.95 C -2.971,-12.54 0,-8.47 0,0 m -34.101,-19.14 v 71.83 c 0,3.63 2.861,6.601 6.6,6.601 3.74,0 6.601,-2.971 6.601,-6.601 V 31.57 c 3.08,3.191 8.359,6.05 14.299,6.05 13.09,0 19.8,-8.8 19.8,-23.54 V -1.319 c 0,-14.741 -6.819,-23.651 -20.13,-23.651 -6.16,0 -11.88,2.97 -14.96,6.491 l -0.66,-2.201 c -0.769,-2.53 -3.08,-4.29 -5.72,-4.29 -3.299,0 -5.83,2.75 -5.83,5.83" /></g><g
|
|
||||||
transform="translate(399.9723,102.311)"
|
|
||||||
id="g48"><path
|
|
||||||
id="path50"
|
|
||||||
style="fill:#464648;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="m 0,0 c 0,9.57 -1.87,14.301 -9.9,14.301 -7.92,0 -9.9,-4.181 -9.9,-14.301 z M -33,-15.069 V 2.2 c 0,14.521 7.479,23.54 23.1,23.54 15.95,0 22.77,-8.689 22.77,-23.54 v -7.37 c 0,-2.859 -2.309,-5.17 -5.17,-5.17 h -27.5 v -5.939 c 0,-4.62 2.86,-9.13 10.89,-9.13 5.72,0 8.8,0.88 13.09,2.97 0.66,0.33 1.54,0.66 2.42,0.66 2.97,0 5.39,-2.42 5.39,-5.391 0,-2.309 -1.429,-3.96 -3.52,-5.17 -5.17,-2.97 -10.23,-4.51 -17.93,-4.51 -15.73,0 -23.54,8.25 -23.54,21.781" /></g><g
|
|
||||||
transform="translate(421.8512,72.061)"
|
|
||||||
id="g52"><path
|
|
||||||
id="path54"
|
|
||||||
style="fill:#464648;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="m 0,0 v 50.16 c 0,3.301 2.53,5.83 5.72,5.83 2.97,0 5.06,-2.09 5.72,-4.949 l 0.55,-2.421 c 3.19,3.191 9.13,7.37 17.16,7.37 13.09,0 18.15,-9.349 18.15,-21.34 V 0 c 0,-3.63 -2.97,-6.6 -6.6,-6.6 -3.63,0 -6.599,2.97 -6.599,6.6 v 31.79 c 0,8.471 -3.411,11.44 -9.571,11.44 -4.73,0 -9.24,-2.86 -11.33,-4.95 L 13.2,0 C 13.2,-3.63 10.23,-6.6 6.6,-6.6 2.97,-6.6 0,-3.63 0,0" /></g><g
|
|
||||||
transform="translate(478.358,89.1118)"
|
|
||||||
id="g56"><path
|
|
||||||
id="path58"
|
|
||||||
style="fill:#464648;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="m 0,0 v 15.29 c 0,14.52 8.36,23.649 24.31,23.649 8.36,0 14.08,-3.08 18.15,-8.029 1.21,-1.54 1.87,-2.75 1.87,-4.511 0,-3.299 -2.53,-5.83 -5.83,-5.83 -1.76,0 -3.08,0.66 -4.4,1.981 -2.75,2.75 -5.39,4.62 -9.79,4.62 -8.69,0 -11.11,-5.83 -11.11,-12.981 L 13.2,1.1 c 0,-7.151 2.75,-12.981 11.44,-12.981 4.4,0 7.04,1.87 9.79,4.62 1.32,1.321 2.31,1.981 4.29,1.981 3.3,0 5.94,-2.531 5.94,-5.83 0,-1.76 -0.66,-2.97 -1.87,-4.51 C 38.72,-20.57 33,-23.65 24.64,-23.65 8.689,-23.65 0,-14.521 0,0" /></g><g
|
|
||||||
transform="translate(530.5396,72.061)"
|
|
||||||
id="g60"><path
|
|
||||||
id="path62"
|
|
||||||
style="fill:#464648;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="m 0,0 v 71.061 c 0,3.629 2.86,6.6 6.6,6.6 3.74,0 6.6,-2.971 6.6,-6.6 v -21.34 c 3.41,2.969 9.02,6.269 16.17,6.269 13.09,0 18.26,-9.349 18.26,-21.34 V 0 c 0,-3.63 -2.859,-6.6 -6.6,-6.6 -3.74,0 -6.6,2.97 -6.6,6.6 v 31.79 c 0,8.471 -3.52,11.44 -9.68,11.44 -4.729,0 -9.46,-2.86 -11.55,-4.95 V 0 C 13.2,-3.63 10.34,-6.6 6.6,-6.6 2.86,-6.6 0,-3.63 0,0" /></g><g
|
|
||||||
transform="translate(249.2096,192.0259)"
|
|
||||||
id="g64"><path
|
|
||||||
id="path66"
|
|
||||||
style="fill:#f1df36;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="m 0,0 h 0.008 l 131.211,0.031 h 0.013 c 3.063,0 6.107,0.66 8.916,1.863 L 65.602,49.549 -8.531,1.7 C -5.83,0.6 -2.923,0 0,0" /></g><g
|
|
||||||
transform="translate(420.2877,374.9341)"
|
|
||||||
id="g68"><path
|
|
||||||
id="path70"
|
|
||||||
style="fill:#faaf42;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="m 0,0 -105.477,-133.359 74.547,-47.655 c 3.392,1.452 6.439,3.697 8.747,6.559 l 75.104,93.431 6.686,8.317 c 1.38,1.714 2.479,3.637 3.289,5.675 0.384,0.965 0.701,1.954 0.95,2.962 z" /></g><g
|
|
||||||
transform="translate(145.3785,311.2251)"
|
|
||||||
id="g72"><path
|
|
||||||
id="path74"
|
|
||||||
style="fill:#faaf42;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="m 0,0 c 0.583,-2.568 1.609,-5.036 3.054,-7.245 0.401,-0.614 0.83,-1.209 1.285,-1.783 l 81.823,-101.735 c 2.396,-2.975 5.588,-5.289 9.138,-6.736 L 169.433,-69.65 62.648,65.424 Z" /></g><g
|
|
||||||
transform="translate(179.4977,457.7324)"
|
|
||||||
id="g76"><path
|
|
||||||
id="path78"
|
|
||||||
style="fill:#9ad7ec;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="m 0,0 c -2.408,-2.762 -4.144,-6.1 -4.985,-9.762 l -29.149,-126.8 c -0.65,-2.826 -0.715,-5.774 -0.239,-8.633 0.073,-0.44 0.155,-0.878 0.254,-1.312 l 62.648,65.424 z" /></g><g
|
|
||||||
transform="translate(484.1334,310.8643)"
|
|
||||||
id="g80"><path
|
|
||||||
id="path82"
|
|
||||||
style="fill:#9ad7ec;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="M 0,0 C 0.837,3.378 0.913,6.943 0.131,10.337 L -29.076,137.21 c -0.791,3.437 -2.374,6.586 -4.566,9.236 L -63.846,64.07 Z" /></g><g
|
|
||||||
transform="translate(317.7506,366.4487)"
|
|
||||||
id="g84"><path
|
|
||||||
id="path86"
|
|
||||||
style="fill:#ffffff;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="M 0,0 40.622,41.329 H 14.038 L -18.791,6.272 V 77.598 H -39.47 V -56.101 h 20.679 v 40.069 l 3.269,3.181 33.46,-43.25 h 27.03 z" /></g><g
|
|
||||||
transform="translate(275.7818,468.8486)"
|
|
||||||
id="g88"><path
|
|
||||||
id="path90"
|
|
||||||
style="fill:#1280c4;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="m 0,0 39.028,53.109 c -0.01,0 -0.022,10e-4 -0.033,10e-4 -0.047,0 -0.094,-0.003 -0.141,-0.003 C 38.521,53.105 38.187,53.099 37.853,53.082 37.814,53.08 37.776,53.072 37.738,53.07 34.783,52.909 31.86,52.166 29.192,50.889 L -89.022,-5.593 c -2.809,-1.342 -5.266,-3.235 -7.262,-5.523 L -67.755,-92.199 0,0.03 Z" /></g><g
|
|
||||||
transform="translate(442.8853,463.2578)"
|
|
||||||
id="g92"><path
|
|
||||||
id="path94"
|
|
||||||
style="fill:#1280c4;fill-opacity:1;fill-rule:nonzero;stroke:none"
|
|
||||||
d="m 0,0 -118.288,56.48 c -3.039,1.455 -6.412,2.215 -9.785,2.22 L -22.598,-88.324 7.606,-5.947 C 5.558,-3.467 2.978,-1.422 0,0" /></g></g></g></g></svg>
|
|
Before Width: | Height: | Size: 10 KiB |
41
mkdocs.yml
Normal file
@ -0,0 +1,41 @@
|
|||||||
|
---
|
||||||
|
site_name: Kube-bench
|
||||||
|
site_url: https://aquasecurity.github.io/kube-bench/
|
||||||
|
site_description: Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark
|
||||||
|
docs_dir: docs/
|
||||||
|
repo_name: GitHub
|
||||||
|
repo_url: https://github.com/aquasecurity/kube-bench/
|
||||||
|
edit_uri: ""
|
||||||
|
|
||||||
|
nav:
|
||||||
|
- Overview: index.md
|
||||||
|
- Getting Started:
|
||||||
|
- Installation: Installation.md
|
||||||
|
- Platforms: Platforms.md
|
||||||
|
- How to run: Running.md
|
||||||
|
- ASFF: asff.md
|
||||||
|
- Flags: Flags_and_commands.md
|
||||||
|
- Configuration Options:
|
||||||
|
- Understanding the yamls: Controls.md
|
||||||
|
- Architecture: Architecture.md
|
||||||
|
- Contributing: Contributing.md
|
||||||
|
|
||||||
|
markdown_extensions:
|
||||||
|
- pymdownx.highlight
|
||||||
|
- pymdownx.superfences
|
||||||
|
- admonition
|
||||||
|
|
||||||
|
extra:
|
||||||
|
generator: false
|
||||||
|
version:
|
||||||
|
method: mike
|
||||||
|
provider: mike
|
||||||
|
|
||||||
|
theme:
|
||||||
|
name: material
|
||||||
|
language: 'en'
|
||||||
|
logo: images/kube-bench-logo-only.png
|
||||||
|
|
||||||
|
plugins:
|
||||||
|
- search
|
||||||
|
- macros
|