8000 GitHub - z3v2cicidi/k8s-security: Kubernetes security notes and best practices
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

z3v2cicidi/k8s-security

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

63 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Kubernetes security

This repo is a collection of kubernetes security stuff and research.

The research was conducted during Summ3r 0f h4ck traineeship.

Overview

  • Security notes

    In-depth research about security of kubernetes features and misconfigurations. Source for all documents below

  • Security hardening and best practices

    A "must do"/best practices list of things to make attacker's life hard

  • Security flags checklist

    A checklist of flags to quickly test if your cluster has security features enabled.

  • Attacker's guide

    A guide for attacker: what to do if he gets to pod/cluster.

    Also, 5E0B some attacks included

  • Vulnerabilities

    Page with sources for security announces and previous vulnerabilities

Tools

  • k8numerator

    Script for enumerating services in kubernetes cluster. Common services dictionary provided.

Slides

References

About

Kubernetes security notes and best practices

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Shell 47.7%
  • Smarty 35.0%
  • Python 17.3%
0