cis-gke-v180-5.10.3
Consider GKE Sandbox for running untrusted workloads (Automated)
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Consider GKE Sandbox for running untrusted workloads (Automated)
Enable Security Posture (Manual)
Ensure GKE clusters are not running using the Compute Engine default service account (Automated)
Prefer using dedicated GCP Service Accounts and Workload Identity (Manual)
Ensure Kubernetes Secrets are encrypted using keys managed in Cloud KMS (Automated)
Ensure the GKE Metadata Server is Enabled (Automated)
Ensure Container-Optimized OS (cos_containerd) is used for GKE Node images (Automated)
Ensure Node Auto-Upgrade is Enabled for GKE Nodes (Automated)
When creating New Clusters - Automate GKE version management using Release Channels (Automated)
Ensure Shielded GKE Nodes are Enabled (Automated)