Prefer using secrets as files over secrets as environment variables (Automated)
Quellsprache: Englisch
Menü
Skills in diesem Repository
SkillsMP hat 7.442 Skills aus CyberStrikeus/CyberStrike gesammelt. Öffne einen Skill, um Quelle und Details zu prüfen.
CyberStrikeus/CyberStrikeEs werden 40 von 7.442 gesammelten Skills angezeigt.
Prefer using secrets as files over secrets as environment variables (Automated)
Quellsprache: Englisch
Consider external secret storage (Manual)
Quellsprache: Englisch
Configure Image Provenance using ImagePolicyWebhook admission controller (Manual)
Quellsprache: Englisch
Create administrative boundaries between resources using namespaces (Manual)
Quellsprache: Englisch
Ensure that the seccomp profile is set to RuntimeDefault in the pod definitions (Automated)
Quellsprache: Englisch
Apply Security Context to Pods and Containers (Manual)
Quellsprache: Englisch
The default namespace should not be used (Automated)
Quellsprache: Englisch
Ensure Image Vulnerability Scanning is enabled (Automated)
Quellsprache: Englisch
Minimize user access to Container Image repositories (Manual)
Quellsprache: Englisch
Minimize cluster access to read-only for Container Image repositories (Manual)
Quellsprache: Englisch
Ensure only trusted container images are used (Manual)
Quellsprache: Englisch
Ensure Kubernetes Web UI is Disabled (Automated)
Quellsprache: Englisch
Ensure that Alpha clusters are not used for production workloads (Automated)
Quellsprache: Englisch
Consider GKE Sandbox for running untrusted workloads (Automated)
Quellsprache: Englisch
Ensure use of Binary Authorization (Automated)
Quellsprache: Englisch
Ensure GKE clusters are not running using the Compute Engine default service account (Automated)
Quellsprache: Englisch
Prefer using dedicated GCP Service Accounts and Workload Identity (Manual)
Quellsprache: Englisch
Ensure Kubernetes Secrets are encrypted using keys managed in Cloud KMS (Automated)
Quellsprache: Englisch
Ensure the GKE Metadata Server is Enabled (Automated)
Quellsprache: Englisch
Ensure Container-Optimized OS (cos_containerd) is used for GKE node images (Automated)
Quellsprache: Englisch
Ensure Node Auto-Repair is enabled for GKE nodes (Automated)
Quellsprache: Englisch
Ensure Node Auto-Upgrade is enabled for GKE nodes (Automated)
Quellsprache: Englisch
When creating New Clusters - Automate GKE version management using Release Channels (Automated)
Quellsprache: Englisch
Ensure Shielded GKE Nodes are Enabled (Automated)
Quellsprache: Englisch
Ensure Integrity Monitoring for Shielded GKE Nodes is Enabled (Automated)
Quellsprache: Englisch
Ensure Secure Boot for Shielded GKE Nodes is Enabled (Automated)
Quellsprache: Englisch
Enable VPC Flow Logs and Intranode Visibility (Automated)
Quellsprache: Englisch
Ensure use of VPC-native clusters (Automated)
Quellsprache: Englisch
Ensure Control Plane Authorized Networks is Enabled (Automated)
Quellsprache: Englisch
Ensure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)
Quellsprache: Englisch
Ensure clusters are created with Private Nodes (Automated)
Quellsprache: Englisch
Consider firewalling GKE worker nodes (Manual)
Quellsprache: Englisch
Ensure use of Google-managed SSL Certificates (Automated)
Quellsprache: Englisch
Ensure Logging and Cloud Monitoring is Enabled (Automated)
Quellsprache: Englisch
Enable Linux auditd logging (Manual)
Quellsprache: Englisch
Ensure authentication using Client Certificates is Disabled (Automated)
Quellsprache: Englisch
Manage Kubernetes RBAC users with Google Groups for GKE (Manual)
Quellsprache: Englisch
Ensure Legacy Authorization (ABAC) is Disabled (Automated)
Quellsprache: Englisch
Enable Customer-Managed Encryption Keys (CMEK) for GKE Persistent Disks (PD) (Manual)
Quellsprache: Englisch
Enable Customer-Managed Encryption Keys (CMEK) for Boot Disks (Automated)
Quellsprache: Englisch