Ensure Shielded GKE Nodes are Enabled (Automated)
Idioma do texto original: inglês
Menu
Skills neste repositório
O SkillsMP coletou 7.442 skills de CyberStrikeus/CyberStrike. Abra uma skill para revisar a origem e os detalhes.
CyberStrikeus/CyberStrikeMostrando 40 de 7.442 skills coletadas.
Ensure Shielded GKE Nodes are Enabled (Automated)
Idioma do texto original: inglês
Ensure Integrity Monitoring for Shielded GKE Nodes is Enabled (Automated)
Idioma do texto original: inglês
Ensure Secure Boot for Shielded GKE Nodes is Enabled (Automated)
Idioma do texto original: inglês
Enable VPC Flow Logs and Intranode Visibility (Automated)
Idioma do texto original: inglês
Ensure use of VPC-native clusters (Automated)
Idioma do texto original: inglês
Ensure Control Plane Authorized Networks is Enabled (Automated)
Idioma do texto original: inglês
Ensure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)
Idioma do texto original: inglês
Ensure clusters are created with Private Nodes (Automated)
Idioma do texto original: inglês
Consider firewalling GKE worker nodes (Manual)
Idioma do texto original: inglês
Ensure use of Google-managed SSL Certificates (Automated)
Idioma do texto original: inglês
Ensure Logging and Cloud Monitoring is Enabled (Automated)
Idioma do texto original: inglês
Enable Linux auditd logging (Manual)
Idioma do texto original: inglês
Ensure authentication using Client Certificates is Disabled (Automated)
Idioma do texto original: inglês
Manage Kubernetes RBAC users with Google Groups for GKE (Manual)
Idioma do texto original: inglês
Ensure Legacy Authorization (ABAC) is Disabled (Automated)
Idioma do texto original: inglês
Enable Customer-Managed Encryption Keys (CMEK) for GKE Persistent Disks (PD) (Manual)
Idioma do texto original: inglês
Enable Customer-Managed Encryption Keys (CMEK) for Boot Disks (Automated)
Idioma do texto original: inglês
Ensure that the proxy kubeconfig file permissions are set to 644 or more restrictive (Automated)
Idioma do texto original: inglês
Ensure that the proxy kubeconfig file ownership is set to root:root (Automated)
Idioma do texto original: inglês
Ensure that the kubelet configuration file has permissions set to 644 (Automated)
Idioma do texto original: inglês
Ensure that the kubelet configuration file ownership is set to root:root (Automated)
Idioma do texto original: inglês
Ensure that the cluster-admin role is only used where required (Manual)
Idioma do texto original: inglês
Avoid non-default bindings to system:authenticated (Automated)
Idioma do texto original: inglês
Minimize access to secrets (Manual)
Idioma do texto original: inglês
Minimize wildcard use in Roles and ClusterRoles (Manual)
Idioma do texto original: inglês
Ensure that default service accounts are not actively used (Automated)
Idioma do texto original: inglês
Ensure that Service Account Tokens are only mounted where necessary (Manual)
Idioma do texto original: inglês
Avoid use of system:masters group (Automated)
Idioma do texto original: inglês
Limit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster (Manual)
Idioma do texto original: inglês
Avoid bindings to system:anonymous (Automated)
Idioma do texto original: inglês
Avoid non-default bindings to system:unauthenticated (Automated)
Idioma do texto original: inglês
Ensure that the cluster enforces Pod Security Standard Baseline profile or stricter for all namespaces (Manual)
Idioma do texto original: inglês
Ensure that the CNI in use supports Network Policies (Manual)
Idioma do texto original: inglês
Ensure that all Namespaces have Network Policies defined (Automated)
Idioma do texto original: inglês
Prefer using secrets as files over secrets as environment variables (Automated)
Idioma do texto original: inglês
Consider external secret storage (Manual)
Idioma do texto original: inglês
Configure Image Provenance using ImagePolicyWebhook admission controller (Manual)
Idioma do texto original: inglês
Create administrative boundaries between resources using namespaces (Manual)
Idioma do texto original: inglês
Ensure that the seccomp profile is set to RuntimeDefault in the pod definitions (Automated)
Idioma do texto original: inglês
Apply Security Context to Pods and Containers (Manual)
Idioma do texto original: inglês