cis-eks-v170-4.5.2
The default namespace should not be used (Automated)
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
The default namespace should not be used (Automated)
Ensure Image Vulnerability Scanning using Amazon ECR image scanning or a third party provider (Automated)
Minimize user access to Amazon ECR (Manual)
Minimize Container Registries to only those approved (Manual)
Prefer using dedicated EKS Service Accounts (Automated)
Ensure Kubernetes Secrets are encrypted using Customer Master Keys (CMKs) managed in AWS KMS (Manual)
Restrict Access to the Control Plane Endpoint (Automated)
Ensure clusters are created with Private Nodes (Automated)
Encrypt traffic to HTTPS load balancers with TLS certificates (Manual)
Manage Kubernetes RBAC users with AWS IAM Authenticator for Kubernetes or Upgrade to AWS CLI v1.16.156 or greater (Manual)