cis-gke-autopilot-v120-4.3.1
Ensure that all Namespaces have Network Policies defined (Automated)
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Ensure that all Namespaces have Network Policies defined (Automated)
Consider external secret storage (Manual)
Configure Image Provenance using ImagePolicyWebhook admission controller (Manual)
Ensure that the seccomp profile is set to RuntimeDefault in the pod definitions (Automated)
The default namespace should not be used (Automated)
Minimize user access to Container Image repositories (Manual)
Minimize cluster access to read-only for Container Image repositories (Manual)
Ensure only trusted container images are used (Automated)
Ensure GKE clusters are not running using the Compute Engine default service account (Automated)
Ensure Kubernetes Secrets are encrypted using keys managed in Cloud KMS (Automated)