Liz Rice
451721a1cf
Add GKE into list of support tests ( #597 )
...
Also adds links to the Kubernetes benchmarks
Fixes #596
4 years ago
Abubakr-Sadik Nii Nai Davis
d988b81540
CIS GKE 1.0.0 benchmark ( #570 )
...
* Add initial commit for CIS GKE 1.0 benchmark
* Update README with GKE instructions
* Fix YAML linter issues
* Set GKE benchmark k8s version to gke-1.0
* Add tests for gke-1.0
Co-authored-by: Roberto Rojas <robertojrojas@gmail.com>
4 years ago
Huang Huang
17cd104788
Fixes issue #574 : change the PATH in container ( #577 )
...
* Fixes issue #574 : change the PATH in container
And change to use `/usr/local/mount-from-host/bin` as mount path.
Fixes #574
* Fix integration tests
4 years ago
Murali Paluru
b677c86868
remove always true for logtostderr ( #548 )
...
* remove always true for logtostderr
* update README for log collection instructions
Co-authored-by: Liz Rice <liz@lizrice.com>
4 years ago
Saurya Das
ca749ccb32
Adding a section for Azure Kubernetes Service ( #495 )
...
* Adding a section for Azure Kubernetes Service
steps to run kube bench on AKS worker nodes
* Update README.md
* Update README.md
Co-authored-by: Roberto Rojas <robertojrojas@gmail.com>
Co-authored-by: Liz Rice <liz@lizrice.com>
4 years ago
Zeid Marouf
299ab36a13
doc: fix ECR image build instructions for EKS mode ( #531 )
4 years ago
Roberto Rojas
af976e6f50
Fixes Issue #494 - add tests for CIS 1.5 ( #530 )
...
* Initial commit.
* Add master and node config.
* Add section 5 of CIS 1.5.1.
* Split sections into section files
* Fix YAML issues.
* adds target translation
* adds target translation
* adds cis-1.5 mapping
* fixed tests
* fixes are per PR
* fixed intergration test
* integration kind test file to appropriate ks8 version
* fixed etcd text
* fixed README
* fixed text
* etcd: fixed grep path
* etcd: fixes
* fixed error message bug
* Update README.md
Co-Authored-By: Liz Rice <liz@lizrice.com>
* Update README.md
Co-Authored-By: Liz Rice <liz@lizrice.com>
* fixes as per PR review
5 years ago
Jonathan Rau
51aa10e354
Update EKS Config & Create EKS Guide ( #489 )
...
* Change EKS Readme
* Fix readme formatting
* Update README.md
Co-Authored-By: Liz Rice <liz@lizrice.com>
* Update README.md
Co-Authored-By: Liz Rice <liz@lizrice.com>
* Update README.md
5 years ago
Soumyadeep Sinha
8e4da53006
Fixed some typos ( #446 )
...
* Fixed some typos
* Fixed some typos
* Fixed typo and capitalization of Kubernetes
* Update README.md
Co-Authored-By: Liz Rice <liz@lizrice.com>
* Update README.md
Co-Authored-By: Liz Rice <liz@lizrice.com>
* Update docs/README.md
Co-Authored-By: Liz Rice <liz@lizrice.com>
* Update docs/README.md
Co-Authored-By: Liz Rice <liz@lizrice.com>
* Update README.md
Co-Authored-By: Liz Rice <liz@lizrice.com>
* Update docs/README.md
Co-Authored-By: Liz Rice <liz@lizrice.com>
* docs: trivial, reinstate capital K
* docs: trivial, reinstate backticks
* docs: trivial, reinstate "in order" for clarity
* docs: trivial, reinstate capital K
5 years ago
Roberto Rojas
7ca438b618
Fixes Issue 269 - Numbering to use CIS Versions ( #511 )
...
* starting benchmark flag
* Revert "starting benchmark flag"
This reverts commit 58fc948626
.
* fixes issue #269
* add more unit tests
* fix bug
* Update cmd/common.go
Co-Authored-By: Liz Rice <liz@lizrice.com>
* fixes as per PR review
* fixes as per PR review
* adds more tests
* fixed tests
* changes as per PR Review
* changes as per PR Review
* updated README
* Update README.md
Co-Authored-By: Liz Rice <liz@lizrice.com>
* Update README.md
Co-Authored-By: Liz Rice <liz@lizrice.com>
* Update README.md
Co-Authored-By: Liz Rice <liz@lizrice.com>
* Update README.md
Co-Authored-By: Liz Rice <liz@lizrice.com>
* changes are per PR review
5 years ago
Alexey Pyltsyn
7a2cc3f554
Improve docs ( #437 )
5 years ago
Mohan Sha
b009520ea3
Added table of contents for navigation ( #455 )
5 years ago
Itay Shakury
3964377a80
add contribution guidelines ( #454 )
5 years ago
Liz Rice
1b49050974
docs: Clarify the meaning of WARN state ( #430 )
...
* docs: Clarify the meaning of WARN state
* Update README.md
5 years ago
Roberto Rojas
a6ee61fd08
Fixes issue #289 : removed versions prior to 1.11 ( #429 )
...
* removed version prior to 1.11
* removed references to kubernetes versions prior to 1.11
5 years ago
James George
050145f6b3
docs: minor tweak ( #438 )
5 years ago
Liz Rice
16beb3e616
docs: note that you may need to be root ( #412 )
5 years ago
Liz Rice
d0d4e95d93
Updated version support ( #385 )
...
Strictly, we don't have the changes in 1.13-json but we do have them in 1.13
5 years ago
Abubakr-Sadik Nii Nai Davis
92df9cb36c
Read kubernetes version from environment ( #390 )
...
* Read kubernetes version from environment
Set kubernetes version to the value of the environment variable `KUBE_BENCH_VERSION` if it is defined and the flag `--version` is not specified on the kube-bench command line.
The command line flag `--version` takes precedence of the environment variable `KUBE_BENCH_VERSION` if both are defined.
* Add info about KUBE_BENCH_VERSION to README
5 years ago
Abubakr-Sadik Nii Nai Davis
2e27d681f7
Remove duplicate documentation. ( #373 )
...
* Remove duplicate documentation.
* Add test configuration header back in main README.
* Add missing regex operator in docs/README.
* Fix incorrect description of configuration options bins, confs etc.
* Move description of version auto-detection to main README.
* Use 1.13 in examples since cfg/1.12 doesn't exist
* Remove duplicate sentence about regex
This sentence is now in the docs/README
* Add link to the docs for test YAML definitions
5 years ago
yoavrotems
7c97f6a490
Add codecov ( #336 )
...
* Update .gitignore
* Update .travis.yml
* Update makefile
* Update .travis.yml
* Update .travis.yml
* Update .travis.yml
* Update README.md
* Update README.md
* Update README.md
* Update makefile
* Update .travis.yml
5 years ago
Liz Rice
08097d2211
Need credentials in order to run kubectl version ( #332 )
...
Without passing in kubeconfig credentials:
```bash
$ docker run --pid=host -v /etc:/etc:ro -v /var:/var:ro -v $(which kubectl):/usr/bin/kubectl -t lizrice/kube-bench:5e6cdfd master -v 1
I0628 16:52:06.591683 6099 util.go:367] Unable to get Kubernetes version from kubectl, using default version: 1.6
I0628 16:52:06.591822 6099 common.go:74] Using benchmark file: cfg/1.6/master.yaml
...
```
As updated in the README with this fix:
```bash
docker run --pid=host -v /etc:/etc:ro -v /var:/var:ro -v $(which kubectl):/usr/bin/kubectl -v ~/.kube:/.kube -e KUBECONFIG=/.kube/config -t lizrice/kube-bench:5e6cdfd master -v 1
I0628 16:53:26.784122 7224 util.go:131] No test file found for 1.14 - using tests for Kubernetes 1.13
I0628 16:53:26.784961 7224 common.go:228] Using config file: cfg/1.13/config.yaml
...
```
5 years ago
Liz Rice
9a900db021
docs: update WIP to draft ( #324 )
5 years ago
Liz Rice
0ab09a85e8
Add pull requests section
...
Add pull requests section
Include instructions for kube-bench version
Other small wording changes
5 years ago
Abubakr-Sadik Nii Nai Davis
7affbc83d8
Add github issue creation instructions.
5 years ago
Liz Rice
c76369fe2c
Add missing quote
5 years ago
Liz Rice
7f2e9b5231
Merge branch 'master' into op-regex
5 years ago
wwwil
7efa7b2c35
Add regex to list of compare ops
5 years ago
Liz Rice
81f0d9c6e3
Merge branch 'master' into Config-doc
5 years ago
Liz Rice
27df1f60ed
Clarification about worker nodes in managed k8s
...
Because we don’t want to put people off running kube-bench altogether in these environments
5 years ago
030
9d0e3491a0
[GH-191] explained that master nodes cannot be inspected in managed k8s
5 years ago
Liz Rice
df3577519c
Document version-specific config files
...
Values in the version-specific files override the main file
5 years ago
Liz Rice
a800ac6ccc
Merge branch 'master' into json-config
5 years ago
Liz Rice
ceb44583dd
Tidy up a couple of things
5 years ago
Liz Rice
f9d0f4acc1
Add OCP info into the README
5 years ago
Liz Rice
a613f6f028
Document job for EKS
5 years ago
Liz Rice
902a10f1c7
Just have one path for both json and yaml
5 years ago
Liz Rice
c887794807
Merge branch 'master' into feature/json-config
5 years ago
Liz Rice
b5f3299e92
Merge branch 'master' into document-output
5 years ago
Liz Rice
df556c2f42
Add CIS & Kubernetes version mapping to README
5 years ago
Liz Rice
488f5221ef
Document output states
...
Also describe how tests can be omitted by editing the YAML
5 years ago
Florent Delannoy
abfc38d672
Update documentation after review
5 years ago
Florent Delannoy
4d3144ca21
Support JSON and YAML configuration
...
Support new configuration options besides --flags:
- JSON file through `jsonpath`
- YAML file through `yamlpath`
These new options are fully backwards-compatible with the existing
tests.
Added a new profile, 1.11-json, that expects a JSON kubelet
configuration file and scores accordingly. This profile is compatible
with EKS.
5 years ago
Cyril Tovena
5baf81a70a
Adds master node detection and a root command that automatically detect checks to run.
...
The root command will run node checks and if possible master checks.
I've also added some Makefile targets to improve local testing and improve the documentation.
5 years ago
Liz Rice
79427e185e
Merge branch 'master' into patch-1
5 years ago
Liz Rice
6b9ceae9d4
True for Windows too
5 years ago
Spencer Owen
2a9a02f25b
warn osx limitation
5 years ago
Liz Rice
8021610e46
For #197 - create job YAML files that mount host volumes as needed
5 years ago
Liz Rice
3a662b3ff6
Merge branch 'master' into doc-kubectl-host-pid
5 years ago
Colin GILLE
af7ad90477
Advise the use to mount /etc & /var read only for docker usage
5 years ago