Have Zarf be able to validate Kubernetes STIGs #34
RothAndrew
started this conversation in
Ideas
Replies: 2 comments 3 replies
-
What would be the reason for integrating compliance checks with ZARF? Maybe consider instead, integrating with big bang itself or equivalent tools that could exist in a cluster. |
Beta Was this translation helpful? Give feedback.
3 replies
-
Interesting: https://medium.com/@LachlanEvenson/kubernetes-hardening-using-kubescape-ab7f9df341cc |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I'm currently looking at STIGs like this one but the way to check that it describes only works if you used
kubeadm
, and we use all kinds of different k8s distros. Better to check from inside the cluster?Using instructions HERE and HERE you could test this manually using
curl
.It would be super awesome if I could just run something like
zarf compliance verify
or something and have it spit out the results of a bunch of checks against these STIGS.Beta Was this translation helpful? Give feedback.
All reactions