criticalstack / swollLinks
an experimental suite of applications and APIs for monitoring kernel-level activity on a live Kubernetes cluster
☆69Updated 4 years ago
Alternatives and similar repositories for swoll
Users that are interested in swoll are comparing it to the libraries listed below
Sorting:
- [EXPERIMENTAL] Extend osquery to report on Kubernetes☆228Updated 4 years ago
- A tool for bootstrapping Kubernetes☆68Updated 4 years ago
- Administrative tooling for Falco☆116Updated this week
- Service implementation for a Kubernetes Dynamic Webhook controller for interacting with Anchore☆65Updated last week
- Cloud Native Security Hub - Security Resources☆54Updated 5 years ago
- agent for handling seccomp descriptors for container runtimes☆47Updated last year
- ☆37Updated 5 years ago
- Kit for building Falco drivers: kernel modules or eBPF probes☆68Updated last week
- MagTape Policy-as-Code for Kubernetes☆151Updated last year
- ⭕️Snooping on the Kubernetes OpenAPI communications☆97Updated last week
- A kubectl plugin which triggers a Sysdig capture☆102Updated 2 years ago
- Manage AppAmormor profiles for Kubernetes cluster☆42Updated 2 years ago
- Kubernetes Pod Security Standards implementation - https://github.com/kubernetes/enhancements/blob/master/keps/sig-auth/2579-psp-replacem…☆101Updated last week
- Envoy External Authorization API Bridge To SPIFFE Workload API☆46Updated last year
- Anchore Kubernetes Inventory can poll Kubernetes Cluster API(s) to tell Anchore Enterprise which Containers and Images are currently in-u…☆67Updated this week
- This is just a proof-of-concept project that aims to sign and verify container images using cosign and OPA (Open Policy Agent)☆63Updated 4 years ago
- Security risk analysis for Kubernetes resources☆76Updated 10 months ago
- Integrates Spiffe and Vault to have secretless authentication☆96Updated 2 weeks ago
- Diagrams to visually learn Falco and its eBPF probe☆15Updated 4 years ago
- A data access control framework for Open Policy Agent☆37Updated last year
- ☆35Updated 4 years ago
- Webhook server that evaluates WebAssembly policies to validate Kubernetes requests☆151Updated this week
- 🔍 Rekor transparency log monitoring and alerting☆27Updated 2 years ago
- Prometheus Metrics Exporter for Falco output events☆121Updated 8 months ago
- ☆33Updated 10 months ago
- A highly configurable build executor and observer designed to generate signed SLSA provenance attestations about build runs.☆70Updated this week
- ☆64Updated last year
- ☆112Updated 7 months ago
- Provides agent and server plugins for SPIRE to allow TPM 2-based node attestation.☆81Updated 2 years ago
- vault-auth-spire is an authentication plugin for Hashicorp Vault which allows logging into Vault using a Spire provided SVID.☆41Updated 2 years ago