mirror of
https://github.com/aquasecurity/kube-bench.git
synced 2024-12-18 20:58:10 +00:00
Merge branch 'master' into Config-doc
This commit is contained in:
commit
81f0d9c6e3
@ -7,6 +7,8 @@
|
|||||||
|
|
||||||
kube-bench is a Go application that checks whether Kubernetes is deployed securely by running the checks documented in the [CIS Kubernetes Benchmark](https://www.cisecurity.org/benchmark/kubernetes/).
|
kube-bench is a Go application that checks whether Kubernetes is deployed securely by running the checks documented in the [CIS Kubernetes Benchmark](https://www.cisecurity.org/benchmark/kubernetes/).
|
||||||
|
|
||||||
|
Note that it is impossible to inspect the master nodes of managed clusters, e.g. GKE, EKS and AKS, using kube-bench as one does not have access to such nodes, although it is still possible to use kube-bench to check worker node configuration in these environments.
|
||||||
|
|
||||||
Tests are configured with YAML files, making this tool easy to update as test specifications evolve.
|
Tests are configured with YAML files, making this tool easy to update as test specifications evolve.
|
||||||
|
|
||||||
![Kubernetes Bench for Security](https://raw.githubusercontent.com/aquasecurity/kube-bench/master/images/output.png "Kubernetes Bench for Security")
|
![Kubernetes Bench for Security](https://raw.githubusercontent.com/aquasecurity/kube-bench/master/images/output.png "Kubernetes Bench for Security")
|
||||||
|
@ -4,8 +4,19 @@
|
|||||||
master:
|
master:
|
||||||
apiserver:
|
apiserver:
|
||||||
bins:
|
bins:
|
||||||
|
- openshift start master api
|
||||||
- hypershift openshift-kube-apiserver
|
- hypershift openshift-kube-apiserver
|
||||||
|
|
||||||
|
scheduler:
|
||||||
|
bins:
|
||||||
|
- "openshift start master controllers"
|
||||||
|
confs:
|
||||||
|
- /etc/origin/master/scheduler.json
|
||||||
|
|
||||||
|
controllermanager:
|
||||||
|
bins:
|
||||||
|
- "openshift start master controllers"
|
||||||
|
|
||||||
etcd:
|
etcd:
|
||||||
bins:
|
bins:
|
||||||
- openshift start etcd
|
- openshift start etcd
|
||||||
|
Loading…
Reference in New Issue
Block a user