The default namespace should not be used (Manual)
Skills in this repository
CyberStrikeus/CyberStrike - Page 55
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Ensure Image Vulnerability Scanning is enabled (Automated)
Minimize user access to Container Image repositories (Manual)
Minimize cluster access to read-only for Container Image repositories (Manual)
Ensure only trusted container images are used (Manual)
Ensure Kubernetes Web UI is Disabled (Automated)
Ensure that Alpha clusters are not used for production workloads (Automated)
Consider GKE Sandbox for running untrusted workloads (Automated)
Ensure GKE clusters are not running using the Compute Engine default service account (Automated)
Prefer using dedicated GCP Service Accounts and Workload Identity (Manual)
Ensure Kubernetes Secrets are encrypted using keys managed in Cloud KMS (Automated)
Ensure the GKE Metadata Server is Enabled (Automated)
Ensure Container-Optimized OS (cos_containerd) is used for GKE node images (Automated)
Ensure Node Auto-Repair is enabled for GKE nodes (Automated)
Ensure Node Auto-Upgrade is enabled for GKE nodes (Automated)
When creating New Clusters - Automate GKE version management using Release Channels (Automated)
Ensure Shielded GKE Nodes are Enabled (Automated)
Ensure Integrity Monitoring for Shielded GKE Nodes is Enabled (Automated)
Ensure Secure Boot for Shielded GKE Nodes is Enabled (Automated)
Enable VPC Flow Logs and Intranode Visibility (Automated)
Ensure use of VPC-native clusters (Automated)
Ensure Control Plane Authorized Networks is Enabled (Automated)
Ensure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)
Ensure clusters are created with Private Nodes (Automated)
Consider firewalling GKE worker nodes (Manual)
Ensure use of Google-managed SSL Certificates (Automated)
Ensure Logging and Cloud Monitoring is Enabled (Automated)
Enable Linux auditd logging (Manual)
Ensure authentication using Client Certificates is Disabled (Automated)
Manage Kubernetes RBAC users with groups in Google Workspace (Manual)
Ensure Legacy Authorization (ABAC) is Disabled (Automated)
Enable Customer-Managed Encryption Keys (CMEK) for GKE Persistent Disks (PD) (Manual)
Enable Customer-Managed Encryption Keys (CMEK) for Boot Disks (Automated)
Ensure that the API server pod specification file permissions are set to 600 or more restrictive (Automated)
Ensure that the Container Network Interface file ownership is set to root:root (Manual)
Ensure that the etcd data directory permissions are set to 700 or more restrictive (Automated)
Ensure that the etcd data directory ownership is set to etcd:etcd (Automated)
Ensure that the default administrative credential file permissions are set to 600 (Automated)
Ensure that the default administrative credential file ownership is set to root:root (Automated)
Ensure that the scheduler.conf file permissions are set to 600 or more restrictive (Automated)