cis-gke-autopilot-v100-4.1.10
Avoid non-default bindings to system:authenticated (Automated)
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Avoid non-default bindings to system:authenticated (Automated)
Minimize access to secrets (Automated)
Ensure that default service accounts are not actively used (Automated)
Ensure that Service Account Tokens are only mounted where necessary (Automated)
Avoid use of system:masters group (Automated)
Limit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster (Manual)
Avoid non-default bindings to system:unauthenticated (Automated)
Ensure that the cluster enforces Pod Security Standard Baseline profile or stricter for all namespaces (Manual)
Ensure that all Namespaces have Network Policies defined (Automated)
Consider external secret storage (Manual)