当前位置:网站首页>CIS基准测试工具kube-bench使用
CIS基准测试工具kube-bench使用
2022-07-05 23:06:00 【识途老码】
CIS基准测试工具kube-bench使用
CIS安全基准

CIS官网: https://www.cisecurity.org/
K8S CIS基准: https://www.cisecurity.org/benchmark/kubernetes
CIS基准测试工具kube-bench

项目地址: https://github.com/aquasecurity/kube-bench
kube-bench基本使用
# 查看kube-bech的使用参数
kube-bench --help

测试项目配置文件
/etc/kube-bench/cfg/是kube-bench的项目测试配置文件的目录.
测试master
kube-apiserver配置参考地址: https://kubernetes.io/zh-cn/docs/reference/command-line-tools-reference/kube-apiserver/kube-apiserver配置文件:/etc/kubernetes/manifests/kube-apiserver.yaml
# 对master进行测试
kube-bench run -s master
# 对master进行测试并只显示FAIL
kube-bench master|grep FAIL
测试node
Kubelet配置参考地址: https://kubernetes.io/zh-cn/docs/reference/command-line-tools-reference/kubelet/
Kubelet配置文件:/etc/kubernetes/kubelet.conf
# 对node进行测试
kube-bench run -s node
测试ETCD
# 对etcd进行测试
kube-bench run -s etcd
边栏推荐
- Fix the memory structure of JVM in one article
- TVS管和ESD管的技术指标和选型指南-嘉立创推荐
- 利用LNMP实现wordpress站点搭建
- poj 2762 Going from u to v or from v to u? (infer whether it is a weak link diagram)
- Non rigid / flexible point cloud ICP registration
- Go language implementation principle -- lock implementation principle
- 2022 R2 mobile pressure vessel filling review simulation examination and R2 mobile pressure vessel filling examination questions
- Basic knowledge of database (interview)
- February 13, 2022 -5- maximum depth of binary tree
- UVA11294-Wedding(2-SAT)
猜你喜欢

Hcip day 12 (BGP black hole, anti ring, configuration)

Hcip day 11 (BGP agreement)

Three. JS VR house viewing

Use of metadata in golang grpc

Data analysis - Thinking foreshadowing

Go language implementation principle -- map implementation principle

2022 G3 boiler water treatment simulation examination and G3 boiler water treatment simulation examination question bank

98. 验证二叉搜索树 ●●

Realize reverse proxy client IP transparent transmission

Marginal probability and conditional probability
随机推荐
From the perspective of quantitative genetics, why do you get the bride price when you get married
Neural structured learning 4 antagonistic learning for image classification
[untitled]
Southeast Asia e-commerce guide, how do sellers layout the Southeast Asia market?
asp. Net pop-up layer instance
Thoroughly understand JVM class loading subsystem
媒体查询:引入资源
(4) UART application design and simulation verification 2 - RX module design (stateless machine)
Using LNMP to build WordPress sites
Data type, variable declaration, global variable and i/o mapping of PLC programming basis (CoDeSys)
How to quickly understand complex businesses and systematically think about problems?
Go language implementation principle -- lock implementation principle
数据库基础知识(面试)
The method and principle of viewing the last modification time of the web page
What is the process of building a website
派对的最大快乐值
Multi camera stereo calibration
PLC编程基础之数据类型、变量声明、全局变量和I/O映射(CODESYS篇 )
UART Application Design and Simulation Verification 2 - TX Module Design (Stateless machine)
[original] what is the core of programmer team management?