用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-aks-v170-5-1-2命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-aks-v170-5.1.2 |
| description | Minimize user access to Azure Container Registry (ACR) (Manual) |
| category | cis-aks |
| version | 1.7.0 |
| author | cyberstrike-official |
| tags | ["cis","aks","kubernetes","azure","acr","iam","access-control","least-privilege"] |
| cis_id | 5.1.2 |
| cis_benchmark | CIS Azure Kubernetes Service (AKS) Benchmark v1.7.0 |
| tech_stack | ["kubernetes","azure","aks"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Restrict user access to Azure Container Registry (ACR), limiting interaction with build images to only authorized personnel and service accounts.
Weak access control to Azure Container Registry (ACR) may allow malicious users to replace built images with vulnerable containers.
Care should be taken not to remove access to Azure ACR for accounts that require this for their operation.
Review Azure Container Registry access permissions to ensure only authorized users and service accounts have access.
Azure Container Registry: If you use Azure Container Registry (ACR) as your container image store, you need to grant permissions to the service principal for your AKS cluster to read and pull images. Currently, the recommended configuration is to use the az aks create or az aks update command to integrate with a registry and assign the appropriate role for the service principal. For detailed steps, see Authenticate with Azure Container Registry from Azure Kubernetes Service.
To avoid needing an Owner or Azure account administrator role, you can configure a service principal manually or use an existing service principal to authenticate ACR from AKS. For more information, see ACR authentication with service principals or Authenticate from Kubernetes with a pull secret.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 3.3 Configure Data Access Control Lists | x | x | x |
| v7 | 14.6 Protect Information through Access Control Lists | x | x | x |