NSA Kubernetes Hardening Guidance [pdf]

This page summarizes the projects mentioned and recommended in the original post on news.ycombinator.com

Our great sponsors
  • InfluxDB - Collect and Analyze Billions of Data Points in Real Time
  • SonarQube - Static code analysis for 29 languages.
  • Mergify - Updating dependencies is time-consuming.
  • cluster-api

    Home for Cluster API, a subproject of sig-cluster-lifecycle

  • kcp

    Kubernetes-like control planes for form-factors and use-cases beyond Kubernetes and container workloads. (by kcp-dev)

    And making it so that "many clusters" look exactly like "one cluster" is one of the goals the kcp prototype was exploring (although still early) because I hear this ALL the time:

    1. 1 cluster was awesome

    2. Many clusters means I rebuild the world

    3. I wish there was a way to get the benefits of one cluster across multiples.

    Which I believe is a solvable problem and partially what we've been poking at at https://github.com/kcp-dev/kcp (although it's still so early that I don't want to get hopes up).

  • InfluxDB

    Collect and Analyze Billions of Data Points in Real Time. Manage all types of time series data in a single, purpose-built database. Run at any scale in any environment in the cloud, on-premises, or at the edge.

  • karmada

    Open, Multi-Cloud, Multi-Cluster Kubernetes Orchestration

  • polaris

    Validation of best practices in your Kubernetes clusters (by FairwindsOps)

    so... a lot of this can be done with Fairwind's OSS tool Polaris... https://github.com/FairwindsOps/polaris

    feels good that we've been addressing this for a bit already tbh.

  • awesome-k8s-security

    A curated list for Awesome Kubernetes Security resources

    Just search for ‘* awesome list’

    https://github.com/magnologan/awesome-k8s-security

    (Unaffiliated with above, just popped up for k8s hardening awesome list)

  • SonarQube

    Static code analysis for 29 languages.. Your projects are multi-language. So is SonarQube analysis. Find Bugs, Vulnerabilities, Security Hotspots, and Code Smells so you can release quality code every time. Get started analyzing your projects today for free.

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts