用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-gke-v170-5-5-5命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-gke-v170-5.5.5 |
| description | Ensure Shielded GKE Nodes are Enabled (Automated) |
| category | cis-gke |
| version | 1.7.0 |
| author | cyberstrike-official |
| tags | ["cis","gke","kubernetes","gcp","node-config","shielded-nodes","secure-boot","vtpm","integrity"] |
| cis_id | 5.5.5 |
| cis_benchmark | CIS Google Kubernetes Engine (GKE) Benchmark v1.7.0 |
| tech_stack | ["kubernetes","gcp","gke"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Shielded GKE Nodes provides verifiable integrity via secure boot, virtual trusted platform module (vTPM)-enabled measured boot, and integrity monitoring.
Shielded GKE nodes protects clusters against boot- or kernel-level malware or rootkits which persist beyond infected OS.
Shielded GKE nodes run firmware which is signed and verified using Google's Certificate Authority, ensuring that the nodes' firmware is unmodified and establishing the root of trust for Secure Boot. GKE node identity is strongly protected via virtual Trusted Platform Module (vTPM) and verified remotely by the master node before the node joins the cluster. Lastly, GKE node integrity (i.e., boot sequence and kernel) is measured and can be monitored and verified remotely.
After Shielded GKE Nodes is enabled in a cluster, any nodes created in a Node pool without Shielded GKE Nodes enabled, or created outside of any Node pool, aren't able to join the cluster.
Shielded GKE Nodes can only be used with Container-Optimized OS (COS), COS with containerd, and Ubuntu node images.
Using Google Cloud Console:
Shielded GKE Nodes are 'Enabled' under the Details pane.Using Command Line:
Run the following command:
gcloud container clusters describe <cluster_name> --format json | jq '.shieldedNodes'
This will return the following if Shielded GKE Nodes are enabled:
{
"enabled": true
}
Note: From version 1.18, clusters will have Shielded GKE nodes enabled by default.
Using Google Cloud Console:
To update an existing cluster to use Shielded GKE nodes:
Shielded GKE NodesDetails pane, under the Security heading, click on the pencil icon named Edit Shields GKE nodes.Enable Shield GKE nodes.SAVE CHANGES.Using Command Line:
To migrate an existing cluster, the flag --enable-shielded-nodes needs to be specified in the cluster update command:
gcloud container clusters update <cluster_name> --zone <cluster_zone> --enable-shielded-nodes
Clusters will have Shielded GKE nodes enabled by default, as of version v1.18
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 16.7 Use Standard Hardening Configuration Templates for Application Infrastructure | x | x | |
| v7 | 5.3 Securely Store Master Images | x | x | |
| v7 | 18.11 Use Standard Hardening Configuration Templates for Databases | x | x |