cis-gke-v170-4.1.6
Avoid use of system:masters group (Automated)
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Avoid use of system:masters group (Automated)
Limit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster (Manual)
Avoid bindings to system:anonymous (Automated)
Avoid non-default bindings to system:unauthenticated (Automated)
Ensure that the cluster enforces Pod Security Standard Baseline profile or stricter for all namespaces (Manual)
Ensure that the CNI in use supports Network Policies (Manual)
Ensure that all Namespaces have Network Policies defined (Automated)
Prefer using secrets as files over secrets as environment variables (Automated)
Configure Image Provenance using ImagePolicyWebhook admission controller (Manual)
Create administrative boundaries between resources using namespaces (Manual)