cis-gke-autopilot-v130-4.1.4
Ensure that default service accounts are not actively used (Automated)
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Ensure that default service accounts are not actively used (Automated)
Ensure that Service Account Tokens are only mounted where necessary (Manual)
Avoid use of system:masters group (Automated)
Limit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster (Manual)
Avoid non-default bindings to system:unauthenticated (Automated)
Ensure that the cluster enforces Pod Security Standard Baseline profile or stricter for all namespaces (Manual)
Ensure that all Namespaces have Network Policies defined (Automated)
Consider external secret storage (Manual)
Configure Image Provenance using ImagePolicyWebhook admission controller (Manual)
Ensure that the seccomp profile is set to RuntimeDefault in the pod definitions (Automated)