当前位置:网站首页>CIS基准测试工具kube-bench使用
CIS基准测试工具kube-bench使用
2022-07-05 23:06:00 【识途老码】
CIS基准测试工具kube-bench使用
CIS安全基准

CIS官网: https://www.cisecurity.org/
K8S CIS基准: https://www.cisecurity.org/benchmark/kubernetes
CIS基准测试工具kube-bench

项目地址: https://github.com/aquasecurity/kube-bench
kube-bench基本使用
# 查看kube-bech的使用参数
kube-bench --help

测试项目配置文件
/etc/kube-bench/cfg/是kube-bench的项目测试配置文件的目录.
测试master
kube-apiserver配置参考地址: https://kubernetes.io/zh-cn/docs/reference/command-line-tools-reference/kube-apiserver/kube-apiserver配置文件:/etc/kubernetes/manifests/kube-apiserver.yaml
# 对master进行测试
kube-bench run -s master
# 对master进行测试并只显示FAIL
kube-bench master|grep FAIL
测试node
Kubelet配置参考地址: https://kubernetes.io/zh-cn/docs/reference/command-line-tools-reference/kubelet/
Kubelet配置文件:/etc/kubernetes/kubelet.conf
# 对node进行测试
kube-bench run -s node
测试ETCD
# 对etcd进行测试
kube-bench run -s etcd
边栏推荐
- Calculating the number of daffodils in C language
- Detailed explanation of pointer and array written test of C language
- Go语言实现原理——锁实现原理
- Live tiktok shop 2022 latest gameplay card slot overseas live e-commerce new traffic
- LeetCode145. Post order traversal of binary tree (three methods of recursion and iteration)
- Dynamic memory management (malloc/calloc/realloc)
- 2.13 summary
- Hcip day 12 (BGP black hole, anti ring, configuration)
- UVA – 11637 Garbage Remembering Exam (组合+可能性)
- February 13, 2022 -5- maximum depth of binary tree
猜你喜欢

Debian 10 installation configuration

数学公式截图识别神器Mathpix无限使用教程

CorelDRAW plug-in -- GMS plug-in development -- new project -- macro recording -- VBA editing -- debugging skills -- CDR plug-in (2)

Selenium+pytest automated test framework practice

Object detection based on impulse neural network

【经典控制理论】自控实验总结

LabVIEW打开PNG 图像正常而 Photoshop打开得到全黑的图像

TVS管和ESD管的技术指标和选型指南-嘉立创推荐
![[screen recording] how to record in the OBS area](/img/34/bd06bd74edcdabaf678c8d7385cae9.jpg)
[screen recording] how to record in the OBS area

Realize reverse proxy client IP transparent transmission
随机推荐
东南亚电商指南,卖家如何布局东南亚市场?
TypeError: this. getOptions is not a function
使用rewrite规则实现将所有到a域名的访问rewrite到b域名
ORB_ SLAM2/3
无刷驱动设计——浅谈MOS驱动电路
(4) UART application design and simulation verification 2 - RX module design (stateless machine)
Go language implementation principle -- lock implementation principle
2022 G3 boiler water treatment simulation examination and G3 boiler water treatment simulation examination question bank
Hj16 shopping list
Debian 10 installation configuration
Hcip day 11 (BGP agreement)
From the perspective of quantitative genetics, why do you get the bride price when you get married
Use of metadata in golang grpc
Week 17 homework
Using LNMP to build WordPress sites
【经典控制理论】自控实验总结
11gR2 Database Services for "Policy" and "Administrator" Managed Databases (文件 I
Registration and skills of hoisting machinery command examination in 2022
Pyqt control part (I)
February 13, 2022-4-symmetric binary tree