kubeaudit
Harbor
Our great sponsors
kubeaudit | Harbor | |
---|---|---|
7 | 74 | |
1,840 | 22,485 | |
2.2% | 2.9% | |
3.8 | 9.7 | |
6 days ago | 2 days ago | |
Go | Go | |
MIT License | Apache License 2.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
kubeaudit
- Looking for Tips on Open Sourcing a kubernetes security tool
-
Interesting tools?
kubeaudit: audit kubernetes or specific manifests for issues https://github.com/shopify/kubeaudit
- kubeaudit
-
Top 6 Kubernetes Security Tools
Here's a link to KubeAudit on Github
-
Introduction to Kubernetes Pentesting
kubeaudit - Audit Kubernetes clusters against common security concerns
-
Kubernetes Security Checklist 2021
Workload configuration should be audited regularly (Kics, Kubeaudit, Kubescape, Conftest, Kubesec, Checkov)
-
2 Widespread Attacks on Your Containerized Environment and 7 Rules to Prevent it.
Kubeaudit
Harbor
-
Docker Private Registry using Harbor
cat << EOF wget \ https://github.com/goharbor/harbor/releases/download/v2.9.4/\ harbor-offline-installer-v2.9.4.tgz EOF
-
Signing container images: Comparing Sigstore, Notary, and Docker Content Trust
Now that you know a little more about Cosign, Notary, and DCT, we will take it one step further by using one of these tools: Cosign. For this example, we will use the simple Docker registry:2 reference image to run a simple registry. In a real-world scenario, a managed registry such as Harbor, Amazon ECR, Docker Hub, etc.
- Docker pull through cache to multiple upstreams, that you can also push to
-
tcp i/o timeout when installing network plugin in "high secure environment"
Have a look at harbor, you can also use it to follow the same methods for helm charts etc.
-
How to build a docker image and still use Watchtower
Or for something more advanced https://goharbor.io/
-
Scan selfhosted docker images for vulnerabilities automatically
Look at https://goharbor.io/
-
Docker has reversed its decision to sunset the “Docker Free Team” plan.
You can host your own image repo if your feeling feisty. Harbor is a graduated project from the CNCF and they are also working on a new implementation called Dragonfly. https://goharbor.io/
- We're no longer sunsetting the Free Team plan | Docker
-
Docker's deleting Open Source images and here's what you need to know
Does anybody know whether there could be something like an open/libre container registry?
Maybe the cloud native foundation or the linux foundation could provide something like this to prevent vendor lock-ins?
I was coincidentially trying out harbor again over the last days, and it seems nice as a managed or self-hosted alternative. [1] after some discussions we probably gonna go with that, because we want to prevent another potential lock-in with sonarpoint's nexus.
Does anybody have similar migration plans?
[1] https://goharbor.io
-
Iron Bank: Secure Registries, Secure Containers
2) Harbor instance registry
What are some alternatives?
kubescape - Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.
Portainer - Making Docker and Kubernetes management easy.
kube-bench - Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark
Dragonfly - This repository has be archived and moved to the new repository https://github.com/dragonflyoss/Dragonfly2.
kubesec - Security risk analysis for Kubernetes resources
phoneinfoga - Information gathering framework for phone numbers
trivy - Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
chartmuseum - helm chart repository server
kube-hunter - Hunt for security weaknesses in Kubernetes clusters
gitlab
polaris - Shopify’s design system to help us work together to build a great experience for all of our merchants.
distribution - The toolkit to pack, ship, store, and deliver container content