GoogleCloudPlatform / gke-secure-defaults-demo
This lab demonstrates some of the security concerns of a default Kubernetes Engine cluster configuration and the corresponding hardening measures to prevent multiple paths of pod escape and cluster privilege escalation.
☆17Updated 5 years ago
Related projects ⓘ
Alternatives and complementary repositories for gke-secure-defaults-demo
- This project demonstrates a series of best practices for improving the security of containerized applications deployed to Kubernetes Engi…☆94Updated 2 months ago
- ☆39Updated 3 years ago
- ☆14Updated 3 months ago
- This project demonstrates a series of best practices for improving the security of containerized applications deployed to Kubernetes Engi…☆69Updated 2 months ago
- Demos for several kubernetes security features☆63Updated 3 years ago
- ☆20Updated 6 months ago
- Report OPA Gatekeeper audit violations in Security Command Center.☆42Updated 2 months ago
- GKE CIS 1.1.0 Benchmark InSpec Profile☆27Updated 3 years ago
- Automated GKE Kubelet Impersonation and Cluster Secret Stealer via kube-env☆102Updated 5 years ago
- Like the unix tree command but for GCP Org Heirarchy☆27Updated 3 years ago
- ☆29Updated 3 years ago
- Dockerfile Security Checker using OPA Rego policies with Conftest☆59Updated 2 years ago
- ☆48Updated 4 years ago
- a tool to audit the istio service mesh☆173Updated 3 years ago
- ☆28Updated 4 years ago
- Owasp Zap chart for Kubernetes☆49Updated 2 years ago
- Security scanning & static analysis tool☆93Updated 3 weeks ago
- Implementation steps and assets for Google Cloud Anthos blueprints https://cloud.google.com/architecture/blueprints/anthos-security-blue…☆44Updated 6 months ago
- ☆24Updated 4 months ago
- Simple tool that allows you to detect imposter commits in GitHub Actions workflows.☆22Updated this week
- RBAC in Kubernetes visualizer☆24Updated 5 years ago
- Kubernetes audit logging, when you don't control the control plane☆65Updated this week
- Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect☆22Updated last week
- Terraform to run Scoutsuite security scan of projects within a Google Cloud Org. Report will be published to a GCS bucket.☆15Updated 6 months ago
- Kubernetes Common Configuration Scoring System☆124Updated 2 years ago
- ☆27Updated last week
- Deploys Zeek on Google Cloud☆25Updated 3 months ago
- OWASP Kubernetes Security Testing Guide☆37Updated 2 months ago
- Time limited, auto-expiring group memberships for users on Google Cloud☆13Updated 2 years ago
- ☆17Updated 6 months ago