Liz Rice
9a900db021
docs: update WIP to draft ( #324 )
5 years ago
Liz Rice
0ab09a85e8
Add pull requests section
...
Add pull requests section
Include instructions for kube-bench version
Other small wording changes
5 years ago
Abubakr-Sadik Nii Nai Davis
7affbc83d8
Add github issue creation instructions.
5 years ago
Liz Rice
c76369fe2c
Add missing quote
5 years ago
Liz Rice
7f2e9b5231
Merge branch 'master' into op-regex
5 years ago
wwwil
7efa7b2c35
Add regex to list of compare ops
5 years ago
Liz Rice
81f0d9c6e3
Merge branch 'master' into Config-doc
5 years ago
Liz Rice
27df1f60ed
Clarification about worker nodes in managed k8s
...
Because we don’t want to put people off running kube-bench altogether in these environments
5 years ago
030
9d0e3491a0
[GH-191] explained that master nodes cannot be inspected in managed k8s
5 years ago
Liz Rice
df3577519c
Document version-specific config files
...
Values in the version-specific files override the main file
5 years ago
Liz Rice
a800ac6ccc
Merge branch 'master' into json-config
6 years ago
Liz Rice
ceb44583dd
Tidy up a couple of things
6 years ago
Liz Rice
f9d0f4acc1
Add OCP info into the README
6 years ago
Liz Rice
a613f6f028
Document job for EKS
6 years ago
Liz Rice
902a10f1c7
Just have one path for both json and yaml
6 years ago
Liz Rice
c887794807
Merge branch 'master' into feature/json-config
6 years ago
Liz Rice
b5f3299e92
Merge branch 'master' into document-output
6 years ago
Liz Rice
df556c2f42
Add CIS & Kubernetes version mapping to README
6 years ago
Liz Rice
488f5221ef
Document output states
...
Also describe how tests can be omitted by editing the YAML
6 years ago
Florent Delannoy
abfc38d672
Update documentation after review
6 years ago
Florent Delannoy
4d3144ca21
Support JSON and YAML configuration
...
Support new configuration options besides --flags:
- JSON file through `jsonpath`
- YAML file through `yamlpath`
These new options are fully backwards-compatible with the existing
tests.
Added a new profile, 1.11-json, that expects a JSON kubelet
configuration file and scores accordingly. This profile is compatible
with EKS.
6 years ago
Cyril Tovena
5baf81a70a
Adds master node detection and a root command that automatically detect checks to run.
...
The root command will run node checks and if possible master checks.
I've also added some Makefile targets to improve local testing and improve the documentation.
6 years ago
Liz Rice
79427e185e
Merge branch 'master' into patch-1
6 years ago
Liz Rice
6b9ceae9d4
True for Windows too
6 years ago
Spencer Owen
2a9a02f25b
warn osx limitation
6 years ago
Liz Rice
8021610e46
For #197 - create job YAML files that mount host volumes as needed
6 years ago
Liz Rice
3a662b3ff6
Merge branch 'master' into doc-kubectl-host-pid
6 years ago
Colin GILLE
af7ad90477
Advise the use to mount /etc & /var read only for docker usage
6 years ago
Martin Mosegaard Amdisen
ba03d8f64b
Document limitation of running with kubectl
...
Once the master node recommended check:
1.1.12 Ensure that the admission control plugin DenyEscalatingExec is set
has been followed, it is no longer possible to run kube-bench itself using kubectl.
6 years ago
Sean Slattery
5ca498cd50
Fix typo on README.md
6 years ago
Liz Rice
bdbbe41b69
Also /var
6 years ago
Liz Rice
ba9985047c
read config files from host /etc
...
I don't see how kube-bench can check the permissions on files unless it has access to them on the host, so I think we need to be mounting the /etc directory from the host
6 years ago
Johannes M. Scheuermann
b3b3cb819a
Correct readme for 1.11 example
...
Signed-off-by: Johannes M. Scheuermann <joh.scheuer@gmail.com>
6 years ago
noqcks
ded5aff482
update README
6 years ago
noqcks
e5c05a97f7
updating README with 1.11 updates
6 years ago
Luke Bond
8894b1dc4f
Update README.md
...
Specify `-t` to get colour in the Docker output.
Added a note about mounting kubectl or kubelet to get the version.
6 years ago
bvwells
cc43fcbb7e
Add link to CIS kubernetes benchmark
6 years ago
Will Medlar
6c7422a938
Migrate dependency management to dep
6 years ago
Abubakr-Sadik Nii Nai Davis
b4b3ebe99c
Add instruction for running kube-bench against a kubernetes cluster.
...
#218
6 years ago
Abubakr-Sadik Nii Nai Davis
609335510a
Remove kube-bench --help output.
...
It has grown stale and no longer reflects the supported options, and can be misleading (see #127 ).
6 years ago
Liz Rice
b26b23e573
Script needs to actually install kube-bench & its config!
6 years ago
Liz Rice
7460037528
Add link to releases page
6 years ago
Will Medlar
1cff0c4da1
Clarify that only Linux is supported when installing from container
6 years ago
Will Medlar
0714683371
Modify entrypoint to allow execution of kube-bench as default
6 years ago
Liz Rice
cb4bec9120
logo instead of heading
7 years ago
Liz Rice
f065893f52
Add logo to readme
7 years ago
clemensw
95769cae83
Update README.md to reflect that the --installation option has been removed.
7 years ago
Liz Rice
1e25e089d0
Minor format update to readme
7 years ago
Lee Briggs
216b1d497a
Fix glide install instructions
7 years ago
Lee Briggs
033ab5638c
Add glide dependencies
...
Also update build from source instructions
7 years ago
Liz Rice
83e58b86db
Update README for Kubernetes 1.8 support
7 years ago
Liz Rice
478e378752
Remove reference to specific benchmark version
...
We support multiple versions of the CIS benchmark
7 years ago
Liz Rice
9a500229a4
Update README for auto-detection of executables and config files
7 years ago
Liz Rice
4e17e3b3d5
Update README.md
7 years ago
Liz Rice
34dd31970a
Update README about installation flag
7 years ago
Liz Rice
44136fa080
Add image and commit badges to README
7 years ago
Liz Rice
0c30f24b59
Travis build name got updated so the badges need updating too
7 years ago
jerbia
432651e85f
Added test 1.4.11 ( #8 )
7 years ago
jerbia
d3bbf2698e
Removed extra '\' sign ( #6 )
...
There was an extra '\' sign in the docker pull command
7 years ago
Amir Jerbi
9a471ef1a4
Added screenshot
7 years ago
Liz Rice
dcd416a521
Executable name changes
...
Updates to travis file, readme and help text
7 years ago
jerbia
3bafeac47c
Update README.md
7 years ago
jerbia
5e4baae23e
Update README.md
7 years ago
jerbia
1d44458e93
Update README.md
7 years ago
jerbia
c53a0ac6f4
Update README.md
7 years ago
Amir Jerbi
55fd838191
No need to run install.sh.
...
Simply clone the project, compile the go app and run ./cis_kubernetes
7 years ago
Liz Rice
26cc77ec1d
Get the tests working on deployments where file names may be different or not in path ( #1 )
...
* Replace the default help text
* Readme file, including the test config format documentation
* Typo
* Warn if config files / executables aren't found
* Ignore original name of executable (as per current README)
* Update tests to avoid failing on stat of a non-existant file
* Add a makefile for ease of build
7 years ago
Liz Rice
7d091c5eba
Minor format change
7 years ago
Liz Rice
e1959b66db
Add README
7 years ago