cis-gke-autopilot-v100-5.4.3
Ensure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Ensure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)
Ensure clusters are created with Private Nodes (Automated)
Ensure use of Google-managed SSL Certificates (Automated)
Manage Kubernetes RBAC users with Google Groups for GKE (Manual)
Avoid non-default bindings to system:authenticated (Automated)
Ensure that default service accounts are not actively used (Automated)
Avoid use of system:masters group (Automated)
Limit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster (Manual)
Avoid non-default bindings to system:unauthenticated (Automated)
Ensure that the cluster enforces Pod Security Standard Baseline profile or stricter for all namespaces (Manual)