oci-seccomp-bpf-hook
kubeaudit
oci-seccomp-bpf-hook | kubeaudit | |
---|---|---|
2 | 7 | |
287 | 1,851 | |
1.4% | 1.2% | |
6.6 | 3.8 | |
4 days ago | about 1 month ago | |
Go | Go | |
Apache License 2.0 | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
oci-seccomp-bpf-hook
-
Securing Containers with Seccomp: Part 1
I was thinking about how to solve that problem, and I thought of an idea: “What if we record the syscalls that a program makes while it’s running?” I was telling one of my co-workers about my idea, and the next day he sent me a link to a tool he found on GitHub. It turned out that some folks at Red Hat had already made a tool called oci-seccomp-bpf-hook that does exactly what I wanted!
-
Kubernetes Security Checklist 2021
The application should have a seccomp, apparmor or selinux profile according to the principles of least privileges (Udica, Oci-seccomp-bpf-hook, Go2seccomp, Security Profiles Operator)
kubeaudit
- Looking for Tips on Open Sourcing a kubernetes security tool
-
Interesting tools?
kubeaudit: audit kubernetes or specific manifests for issues https://github.com/shopify/kubeaudit
- kubeaudit
-
Top 6 Kubernetes Security Tools
Here's a link to KubeAudit on Github
-
Introduction to Kubernetes Pentesting
kubeaudit - Audit Kubernetes clusters against common security concerns
-
Kubernetes Security Checklist 2021
Workload configuration should be audited regularly (Kics, Kubeaudit, Kubescape, Conftest, Kubesec, Checkov)
-
2 Widespread Attacks on Your Containerized Environment and 7 Rules to Prevent it.
Kubeaudit
What are some alternatives?
grype - A vulnerability scanner for container images and filesystems
kubescape - Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.
falco - Cloud Native Runtime Security
kube-bench - Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark
hadolint - Dockerfile linter, validate inline bash, written in Haskell
kubesec - Security risk analysis for Kubernetes resources
documentation - Kata Containers version 1.x documentation (for version 2.x see https://github.com/kata-containers/kata-containers).
trivy - Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
kube-hunter - Hunt for security weaknesses in Kubernetes clusters
checkov - Prevent cloud misconfigurations and find vulnerabilities during build-time in infrastructure as code, container images and open source packages with Checkov by Bridgecrew.
polaris - Shopify’s design system to help us work together to build a great experience for all of our merchants.