kubebench profile for Yandex Managed Service for Kubernetes #1065
-
Good afternoon! We saw a comment on the kubebench page: We have already contacted the CIS community to create our own CIS Benchmark, but in order not to waste time, we would like to clarify something. In this regard, there are several questions:
|
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 3 replies
-
There is an example of how to add a new benchmark via only updating files in https://github.com/aquasecurity/kube-bench/compare/main...mozillazg:new-benchmark-demo?expand=1
|
Beta Was this translation helpful? Give feedback.
-
Hey as @mozillazg answered you can see how to run a new benchmark for debugging and yes this is a good point to start by using basic cis and go from there.
Mostly we accepting CIS approved benchmarks, but in some cases with strong validation we do accept other. for example redhat ocp hardening guide, we worked with the fellows in redhat about it and accept it because they are the ocp creators (two years later it really become CIS and rhel collaboration).
You can read CONTRIBUTING.md about our guide line,
About GKE you are right it's better not to be like that, there are a few reasons for that,
I think @mozillazg covered this part ( P.S you are welcome to make a PR about it into contribution in docs) |
Beta Was this translation helpful? Give feedback.
Hey as @mozillazg answered you can see how to run a new benchmark for debugging and yes this is a good point to start by using basic cis and go from there.
Mostly we accepting CIS approved benchmarks, but in some cases with strong validation we do accept other. for example redhat ocp hardening guide, we worked with the fellows in redhat about it and accept it because they are the ocp creators (two years later it really become CIS and rhel collaboration).