connaisseur
An admission controller that integrates Container Image Signature Verification into a Kubernetes cluster (by sse-secure-systems)
kubestriker
A Blazing fast Security Auditing tool for Kubernetes (by vchinnipilli)
connaisseur | kubestriker | |
---|---|---|
3 | 8 | |
418 | 978 | |
0.5% | 0.1% | |
9.0 | 0.0 | |
7 days ago | 26 days ago | |
Go | Python | |
Apache License 2.0 | Apache License 2.0 |
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
connaisseur
Posts with mentions or reviews of connaisseur.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2021-11-16.
-
Container security best practices: Comprehensive guide
We already mentioned Connaisseur Admission Controller as a way to enforce content trust and reject images that are not signed by trusted sources.
- GitHub - sse-secure-systems/connaisseur: An admission controller that integrates Container Image Signature Verification into a Kubernetes cluster
-
Making the Internet more secure one signed container at a time
Admission Controller was based on Connaisseur, heavily modified to work with v2 instead of v1 signatures.
kubestriker
Posts with mentions or reviews of kubestriker.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2022-01-15.
-
Top 200 Kubernetes Tools for DevOps Engineer Like You
TerraScan - Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure. klum - Kubernetes Lazy User Manager Kyverno - Kubernetes Native Policy Management https://kyverno.io kiosk - kiosk office Multi-Tenancy Extension For Kubernetes - Secure Cluster Sharing & Self-Service Namespace Provisioning kube-bench - CIS Kubernetes Benchmark tool kube-hunter - Pentesting tool - Hunts for security weaknesses in Kubernetes clusters kube-who-can - Show who has RBAC permissions to perform actions on different resources in Kubernetes starboard - Kubernetes-native security toolkit Simulator - Kubernetes Security Training Platform - Focussing on security mitigation RBAC Lookup - Easily find roles and cluster roles attached to any user, service account, or group name in your Kubernetes cluster https://fairwinds.com Kubeaudit - kubeaudit helps you audit your Kubernetes clusters against common security controls Gangway - An application that can be used to easily enable authentication flows via OIDC for a kubernetes cluster Audit2rbac - Autogenerate RBAC policies based on Kubernetes audit logs Chartsec - Helm Chart security scanner kubestriker - Security Auditing tool Datree - CLI tool to prevent K8s misconfigurations by ensuring that manifests and Helm charts follow best practices as well as your organization’s policies Krane - Kubernetes RBAC static Analysis & visualisation tool Flaco - The Falco Project - Cloud-Native runtime security Clair - Vulnerability Static Analysis for Containers Anchore Cli - Coomand Line Interface built on top of anchore engine to manage and inspect images, policies, subscriptions and registries Project Quay - Container image registry designed to boost the security of your repositories via vulnerability scanning and tight access control Kubescape - Tool to test if Kubernetes is deployed securely according to multiple frameworks: regulatory, customized company policies and DevSecOps best practices, such as the NSA-CISA and the MITRE ATT&CK®
-
Container security best practices: Comprehensive guide
Other tools you can use are linux-bench, docker-bench, kube-bench, kube-hunter, kube-striker, Cloud Custodian, OVAL, and OS Query.
- vchinnipilli/kubestriker - A Blazing fast Security Auditing tool for Kubernetes
- Kuberentes Security Auditing tool for devops and security professionals
- A fast Security Auditing tool for Kubernetes
- Kubestriker - A blazing fast Kubernetes security auditing tool
-
Kubestriker - A blazing fast Kubernetes security auditing tool for free
# Create python virtual environment $ python3 -m venv env # Activate python virtual environment $ source env/bin/activate # Clone this repository $ git clone https://github.com/vchinnipilli/kubestriker.git # Go into the repository $ cd kubestriker # Install dependencies $ pip install -r requirements.txt # Incase of prompt toolkit or selectmenu errors $ pip install prompt-toolkit==1.0.15 $ pip install -r requirements.txt # Gearing up Kubestriker $ python -m kubestriker # Result will be generated in the current working directory with the name of the target
- Kubestriker - A Blazing fast Security Auditing tool for kubernetes!!
What are some alternatives?
When comparing connaisseur and kubestriker you can also consider the following projects:
cosign - Code signing and transparency for containers and binaries
ScoutSuite - Multi-Cloud Security Auditing Tool
gatekeeper - 🐊 Gatekeeper - Policy Controller for Kubernetes
opencspm - Open Cloud Security Posture Management Engine
enhancements - Enhancements tracking repo for Kubernetes
SonarQube - Continuous Inspection
gatekeeper-library - 📚 The OPA Gatekeeper policy library
cloudsploit - Cloud Security Posture Management (CSPM)
magtape - MagTape Policy-as-Code for Kubernetes
pixie - Instant Kubernetes-Native Application Observability
cfn_nag - Linting tool for CloudFormation templates
cloud-explorer - An API Gateway for Multi Cloud provider
connaisseur vs cosign
kubestriker vs ScoutSuite
connaisseur vs gatekeeper
kubestriker vs opencspm
connaisseur vs enhancements
kubestriker vs SonarQube
connaisseur vs gatekeeper-library
kubestriker vs cloudsploit
connaisseur vs magtape
kubestriker vs pixie
connaisseur vs cfn_nag
kubestriker vs cloud-explorer