Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CIS Kubernetes Benchmark Profile on EKS #31

Closed
adam-yield opened this issue Apr 18, 2021 · 3 comments
Closed

CIS Kubernetes Benchmark Profile on EKS #31

adam-yield opened this issue Apr 18, 2021 · 3 comments

Comments

@adam-yield
Copy link

I am unable to run InSpec.io cis-k8s-benchmark on my EKS cluster, it'd be nice to have a flag via the cli to provide the cluster arn resource and to run the benchmark against the remote eks cluster.

I couldn't find any information in the README.md file, maybe you have a solution in place you could share with me?

@schurzi
Copy link
Contributor

schurzi commented Apr 24, 2021

If I understand correctly you want to specify an ARN to inspec/cinc-auditor when executin the profile. This ARN would point to your K8s cluster in AWS and hen the profile should be executed on alle nodes in the cluster?

The way I understand this issue I think we can't help you. This would be a feature that has to be provided by the executor (inspec or cinc-auditor). As far as I know the executors support local, ssh or docker connections. If you can establish an easy was to get all hostnames of your EKS nodes, you could run a loop and execute the profile via SSH. To get this working you can use the -t option (https://docs.chef.io/inspec/cli#exec).

@adam-yield
Copy link
Author

Yes you understood me correctly, thanks for the prompt reply.

@schurzi
Copy link
Contributor

schurzi commented May 5, 2021

if you find/create a good solution for this, it would be nice to drop a link here. For now I will close this issue, since this is out of scope for us.

@schurzi schurzi closed this as completed May 5, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants