当前位置:网站首页>CIS benchmark tool Kube bench

CIS benchmark tool Kube bench

2022-07-05 23:23:00 Know the old code

CIS Safety benchmark

 Insert picture description here
CIS Official website : https://www.cisecurity.org/
K8S CIS The benchmark : https://www.cisecurity.org/benchmark/kubernetes


CIS Benchmarking tools kube-bench

 Insert picture description here
Project address : https://github.com/aquasecurity/kube-bench


kube-bench Basic use

#  see kube-bech Using parameters of 
kube-bench --help

 Insert picture description here


Test project configuration file

/etc/kube-bench/cfg/ yes kube-bench Directory of project test configuration files .
 Insert picture description here


test master

kube-apiserver To configure Reference address : https://kubernetes.io/zh-cn/docs/reference/command-line-tools-reference/kube-apiserver/
kube-apiserver The configuration file :/etc/kubernetes/manifests/kube-apiserver.yaml

#  Yes master To test 
kube-bench run -s master

#  Yes master Test and display only FAIL
kube-bench master|grep FAIL

test node

Kubelet To configure Reference address : https://kubernetes.io/zh-cn/docs/reference/command-line-tools-reference/kubelet/

Kubelet The configuration file :/etc/kubernetes/kubelet.conf

#  Yes node To test 
kube-bench run -s node

test ETCD

#  Yes etcd To test 
kube-bench run -s etcd
原网站

版权声明
本文为[Know the old code]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/186/202207052306511836.html