All Projects → ksoclabs → awesome-kubernetes-security

ksoclabs / awesome-kubernetes-security

Licence: other
A curated list of awesome Kubernetes security resources

Projects that are alternatives of or similar to awesome-kubernetes-security

policy-server
Webhook server that evaluates WebAssembly policies to validate Kubernetes requests
Stars: ✭ 111 (-85.68%)
Mutual labels:  kubernetes-security
Checkov
Prevent cloud misconfigurations during build-time for Terraform, Cloudformation, Kubernetes, Serverless framework and other infrastructure-as-code-languages with Checkov by Bridgecrew.
Stars: ✭ 3,572 (+360.9%)
Mutual labels:  kubernetes-security
Kube Bench
Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark
Stars: ✭ 4,359 (+462.45%)
Mutual labels:  kubernetes-security
awesome-falco
A curated list of Falco related tools, frameworks, blogs, podcasts, and articles
Stars: ✭ 166 (-78.58%)
Mutual labels:  kubernetes-security
CloudAndContainerCompromiseSimulator
Simulates a compromise in a cloud and container environment
Stars: ✭ 20 (-97.42%)
Mutual labels:  kubernetes-security
k0otkit
k0otkit is a universal post-penetration technique which could be used in penetrations against Kubernetes clusters.
Stars: ✭ 217 (-72%)
Mutual labels:  kubernetes-security
awesome-cloud-native-security
awesome resources about cloud native security 🐿
Stars: ✭ 233 (-69.94%)
Mutual labels:  kubernetes-security

🔒 awesome-kubernetes-security Awesome

A curated list of awesome Kubernetes security resources. Can you dig it?

Open Source Projects

  • aad-pod-identity - Assign Azure AD idenitites to pods in Kubernetes, in order to access Azure resources
  • audit2rbac - Autogenerate RBAC policies based on Kubernetes audit logs
  • Deepfence ThreatMapper - Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless
  • cnspec - Scan Kubernetes clusters, containers, and manifest files for vulnerabilities and misconfigurations
  • falco - Container Native Runtime Security
  • kdigger - Kubernetes focused container assessment and context discovery tool for penetration testing
  • kiam - Integrate AWS IAM with Kubernetes
  • kube-bench - Check whether Kubernetes is deployed according to security best practics
  • kube-hunter - Hunt for security weaknesses in Kubernetes clusters
  • kube-psp-advisor - Help building an adaptive and fine-grained pod security policy
  • kube-scan - k8s cluster risk assessment tool
  • Kubei - Vulnerabilities scanner for Kubernetes clusters
  • kube2iam - Provide different AWS IAM roles for pods running on Kubernetes
  • kubeaudit - Audit your Kubernetes clusters against common security controls
  • kubectl-bindrole - Find Kubernetes roles bound to a specified ServiceAccount, Group or User
  • kubectl-dig - Deep Kubernetes visibility from the kubectl
  • kubectl-kubesec - Scan Kubernetes pods, deployments, daemonsets and statefulsets with kubesec.io
  • kubectl-who-can - Show who has permissions to <verb> <resource> in Kubernetes
  • OWASP Top Ten for Kubernetes - The Top Ten is a prioritized list of these risks backed by data collected from organizations varying in maturity and complexity
  • terrascan - Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure
  • kyverno - Kubernetes Native Policy Management
  • rakkess - Review access matrix for Kubernetes server resources
  • rback - RBAC in Kubernetes visualizer
  • steampipe - Use SQL to query your cloud services (AWS, Azure, GCP and more) running Kubernetes
  • steampipe-kubernetes - Use SQL to query your Kubernetes resources
  • steampipe-kubernetes-compliance - Kubernetes compliance scanning tool for CIS, NSA & CISA Cybersecurity technical report for Kubernetes hardening.
  • trivy - A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable for CI
  • kubernetes-rbac-audit - Tool for auditing RBACs in Kubernetes
  • kubernetes-external-secrets - Tool to get External Secrets from Hashicorp Vault and AWS SSM
  • vault-secrets-operator - An operator to create Kubernetes secrets from Vault for a secure GitOps based workflow

General Resources

Twitter Accounts

Note that the project description data, including the texts, logos, images, and/or trademarks, for each open source project belongs to its rightful owner. If you wish to add or remove any projects, please contact us at [email protected].