mirror of
https://github.com/aquasecurity/kube-bench.git
synced 2025-02-22 20:42:08 +00:00
data:image/s3,"s3://crabby-images/5ec75/5ec753ac06e490927a920aa72ff26bf24c04f59c" alt="Yoav Rotem"
* Delete README.md * Edit readme and separate into different files * Update README.md * Update Running.md * Update CONTRIBUTING.md * Create Contributing.md * Add files via upload * Update Index.md * Rename Flags and Commands.md to Flags_and_commands.md * Rename Index.md to index.md * Create mkdocs.yml * Delete images directory * Update README.md * Update README.md * Update README.md * Update README.md * Update README.md * Update README.md * Create mkdocs-dev.yaml * Create mkdocs-latest.yaml * Update mkdocs.yml * Update mkdocs.yml * Update mkdocs.yml Add yamllint --- * Make it yamllint comply * Make Yamllint comply * Make Yamllint comply * Change description Co-authored-by: Itay Shakury <itay@itaysk.com> * Fix syntax Co-authored-by: Itay Shakury <itay@itaysk.com> * Update docs/Architecture.md Co-authored-by: Itay Shakury <itay@itaysk.com> * Update docs/Architecture.md Co-authored-by: Itay Shakury <itay@itaysk.com> * Update example for test files * Update contributing * Delete Contributing.md * Update Flags_and_commands.md * Change syntax and add source * Update Platforms.md * lower case file names * lower case file names * Lower case file names * Lower case file names * Lower case file names * Lower case file names * Add note about inspect master in some platforms * Add quick start * Lower case files names * Lower case files names * Fixing typo * Remove section about old ocp * Fix typos Co-authored-by: Itay Shakury <itay@itaysk.com>
36 lines
2.8 KiB
Markdown
36 lines
2.8 KiB
Markdown
[download]: https://img.shields.io/github/downloads/aquasecurity/kube-bench/total?logo=github
|
|
[release-img]: https://img.shields.io/github/release/aquasecurity/kube-bench.svg?logo=github
|
|
[release]: https://github.com/aquasecurity/kube-bench/releases
|
|
[docker-pull]: https://img.shields.io/docker/pulls/aquasec/kube-bench?logo=docker&label=docker%20pulls%20%2F%20kube-bench
|
|
[cov-img]: https://codecov.io/github/aquasecurity/kube-bench/branch/main/graph/badge.svg
|
|
[cov]: https://codecov.io/github/aquasecurity/kube-bench
|
|
[report-card-img]: https://goreportcard.com/badge/github.com/aquasecurity/kube-bench
|
|
[report-card]: https://goreportcard.com/report/github.com/aquasecurity/kube-bench
|
|
|
|
data:image/s3,"s3://crabby-images/8703e/8703e7ecff28db28518e771cabef46e0e1dcb0eb" alt="Kube-bench Logo"
|
|
[![GitHub Release][release-img]][release]
|
|
![Downloads][download]
|
|
![Docker Pulls][docker-pull]
|
|
[![Go Report Card][report-card-img]][report-card]
|
|
[data:image/s3,"s3://crabby-images/b2f69/b2f69f27d19baccd9ea105e8982b0e1d85c1804c" alt="Build Status"](https://github.com/aquasecurity/kube-bench/actions)
|
|
[data:image/s3,"s3://crabby-images/17683/1768380119c0c89a3a7922cc565ecc789708079d" alt="License"](https://github.com/aquasecurity/kube-bench/blob/main/LICENSE)
|
|
[data:image/s3,"s3://crabby-images/74296/74296466fcb464d26253133e177c18f64ec5bf19" alt="Docker image"](https://microbadger.com/images/aquasec/kube-bench "Get your own image badge on microbadger.com")
|
|
[data:image/s3,"s3://crabby-images/ace21/ace2150ff9590c2a2169b5448203d6da2376f1d9" alt="Source commit"](https://microbadger.com/images/aquasec/kube-bench)
|
|
[![Coverage Status][cov-img]][cov]
|
|
|
|
|
|
# Kube-bench
|
|
|
|
kube-bench is a Go application that checks whether Kubernetes is deployed securely by running the checks documented in the [CIS Kubernetes Benchmark](https://www.cisecurity.org/benchmark/kubernetes/).
|
|
|
|
Tests are configured with YAML files, making this tool easy to update as test specifications evolve.
|
|
|
|
|
|
1. kube-bench implements the [CIS Kubernetes Benchmark](https://www.cisecurity.org/benchmark/kubernetes/) as closely as possible. Please raise issues here if kube-bench is not correctly implementing the test as described in the Benchmark. To report issues in the Benchmark itself (for example, tests that you believe are inappropriate), please join the [CIS community](https://cisecurity.org).
|
|
|
|
1. There is not a one-to-one mapping between releases of Kubernetes and releases of the CIS benchmark. See [CIS Kubernetes Benchmark support](#cis-kubernetes-benchmark-support) to see which releases of Kubernetes are covered by different releases of the benchmark.
|
|
|
|
1. It is impossible to inspect the master nodes of managed clusters, e.g. GKE, EKS, AKS and ACK, using kube-bench as one does not have access to such nodes, although it is still possible to use kube-bench to check worker node configuration in these environments.
|
|
|
|
For help and more information go to our [github discussions q&a](https://github.com/aquasecurity/kube-bench/discussions/categories/q-a)
|