cis-gke-v180-5.7.2
Enable Linux auditd logging (Manual)
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Enable Linux auditd logging (Manual)
Ensure authentication using Client Certificates is Disabled (Automated)
Enable Customer-Managed Encryption Keys (CMEK) for GKE Persistent Disks (PD) (Manual)
Enable Customer-Managed Encryption Keys (CMEK) for Boot Disks (Automated)
Ensure that the proxy kubeconfig file permissions are set to 644 or more restrictive (Automated)
Ensure that the proxy kubeconfig file ownership is set to root:root (Automated)
Ensure that the kubelet configuration file has permissions set to 644 (Automated)
Ensure that the kubelet configuration file ownership is set to root:root (Automated)
Ensure that the cluster-admin role is only used where required (Manual)
Avoid non-default bindings to system:authenticated (Automated)