ref: https://www.cncf.io/blog/2021/09/03/kubescape-the-first-open-source-tool-for-running-nsa-and-cisa-kubernetes-hardening-tests/
本篇文章是一個專案介紹文,該專案是個名為 Kubescape 的安全性掃描專案,該專案主要是用來檢驗目標 Kubernetes 是否能夠通過 NSA/CISA 等安全性檢查。
National Security Agency(NSA) 以及 Cybersecurity and Infrastructure Security Agency (CISA) 最近有發佈一個高達 52 頁的安全性指南,
該指南探討如何設立與強化 Kubernetes 叢集的安全性。
https://media.defense.gov/2021/Aug/03/2002820425/-1/-1/1/CTR_KUBERNETES%20HARDENING%20GUIDANCE.PDF
而 Kubescape 專案是一個基於 OPA(OpenPolicyAgent) 引擎的安全性檢查專案,該專案會從 Kubernetes API 取得各類型 Kubernetes 專案的資訊並且針對這些資訊去進行檢查。
檢查是基於上述 NSA/CISA 發布的安全性報告,該檢查的類別包含
1. Non-root containers
2. Immutable container filesystem
3. Building secure container images
4. Privileged containers
5. hostPID, hostIPC privileges
6. hostNetwork access
7. allowedHostPaths field
8. Protecting pod service account tokens
9. Pods in kube-system and kube-public
10. Resource policies
11. Control plane hardening
12. Encrypted secrets
13. Anonymous Requests
有興趣的可以試試看這個專案
「cybersecurity and infrastructure security agency」的推薦目錄:
- 關於cybersecurity and infrastructure security agency 在 矽谷牛的耕田筆記 Facebook 的最佳貼文
- 關於cybersecurity and infrastructure security agency 在 Engadget Facebook 的精選貼文
- 關於cybersecurity and infrastructure security agency 在 Engadget Facebook 的最讚貼文
- 關於cybersecurity and infrastructure security agency 在 Cybersecurity and Infrastructure Security Agency - Facebook 的評價
- 關於cybersecurity and infrastructure security agency 在 Cisagov - Cybersecurity and Infrastructure Security Agency 的評價
- 關於cybersecurity and infrastructure security agency 在 Cyber Infrastructure Security Agency, protecting critical ... 的評價
cybersecurity and infrastructure security agency 在 Engadget Facebook 的精選貼文
Without presenting evidence, the president claimed the 2020 election that he lost was 'inaccurate' and fired the man in charge of its security.
cybersecurity and infrastructure security agency 在 Engadget Facebook 的最讚貼文
Despite baseless claims spread by the president, CISA said there's 'no evidence' of compromised results.
cybersecurity and infrastructure security agency 在 Cisagov - Cybersecurity and Infrastructure Security Agency 的推薦與評價
Commit today, secure tomorrow. Cybersecurity and Infrastructure Security Agency has 322 repositories available. Follow their code on GitHub. ... <看更多>
cybersecurity and infrastructure security agency 在 Cyber Infrastructure Security Agency, protecting critical ... 的推薦與評價
... <看更多>
cybersecurity and infrastructure security agency 在 Cybersecurity and Infrastructure Security Agency - Facebook 的推薦與評價
Cybersecurity and Infrastructure Security Agency ... This senior leadership position will guide the Threat Hunt Team, and is responsible for the development… More ... ... <看更多>