cis-gke-autopilot-v100-4.5.1
Configure Image Provenance using ImagePolicyWebhook admission controller (Manual)
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Configure Image Provenance using ImagePolicyWebhook admission controller (Manual)
Create administrative boundaries between resources using namespaces (Manual)
Ensure that the seccomp profile is set to RuntimeDefault in the pod definitions (Automated)
The default namespace should not be used (Automated)
Minimize user access to Container Image repositories (Manual)
Minimize cluster access to read-only for Container Image repositories (Manual)
Ensure only trusted container images are used (Automated)
Ensure GKE clusters are not running using the Compute Engine default service account (Automated)
Ensure Kubernetes Secrets are encrypted using keys managed in Cloud KMS (Automated)
Enable VPC Flow Logs and Intranode Visibility (Automated)