d2iq-archive / kubernetes-security-benchmark
A simple way to evaluate the security of your Kubernetes deployment against sets of best practices defined by various community sources
☆28Updated 5 years ago
Alternatives and similar repositories for kubernetes-security-benchmark:
Users that are interested in kubernetes-security-benchmark are comparing it to the libraries listed below
- Alcide Kubernetes Audit Log Analyzer - Alcide kAudit☆36Updated 3 years ago
- Links and resources for the O'Reilly Kubernetes Security book☆98Updated 4 years ago
- Cloud Native Security Hub - Security Resources☆54Updated 4 years ago
- Falco container runtime security extras (default rulesets and more)☆49Updated 5 years ago
- The Container Security Book—a free book for practitioners☆82Updated 4 years ago
- Dockerfile Security Checker using OPA Rego policies with Conftest☆59Updated 2 years ago
- A Dockerfile that creates an image with known vulnerabilities.☆49Updated 3 years ago
- Kubernetes admission webhook that uses cosign verify to check the subject and issuer of the image matches what you expect☆23Updated last week
- INTERCEPT / Policy as Code Auditing & Compliance☆83Updated 3 weeks ago
- a tool to audit the istio service mesh☆174Updated 3 years ago
- Container Security Workshop covering using Falco on Kubernetes.☆105Updated 3 years ago
- ☆33Updated 5 years ago
- ☆29Updated 2 weeks ago
- Owasp Zap chart for Kubernetes☆48Updated 3 years ago
- RBAC in Kubernetes visualizer☆24Updated 5 years ago
- Kubernetes Common Configuration Scoring System☆124Updated 2 years ago
- Fetch encrypted files from S3 bucket and decrypt them using AWS KMS☆13Updated 6 years ago
- A static analysis tool for Terraform plans.☆45Updated 2 years ago
- ☆25Updated 9 months ago
- Automated GKE Kubelet Impersonation and Cluster Secret Stealer via kube-env☆102Updated 5 years ago
- A Terraform module to create and maintain Kubernetes clusters on AWS easily, relying entirely on kops☆38Updated 2 years ago
- Darkbit Cloud Security Tools☆25Updated 4 years ago
- Kubernetes operator for Falco that allows developers to manage rules for detecting intruders and backdoors☆68Updated 4 years ago
- Coordinate deployments in Kubernetes with external platforms.☆15Updated 2 years ago
- Aqua Enterprise scanner as a plug-in vulnerability scanner in the Harbor registry☆36Updated 4 months ago
- cloud native software supply chain ☁️🔗☆63Updated 4 years ago
- A POC for DNS spoofing in kubernetes clusters. Runs with minimum capabilities, on default installations of kuberentes.☆77Updated 5 years ago
- Notes from KubeCon and EnvoyCon 2019☆28Updated 5 years ago
- Enable Falco to read audit logs from EKS☆11Updated 4 years ago
- Kubernetes security scanner based on the open-source container vulnerability scanner Trivy.☆23Updated 4 years ago