cis-gke-v190-5.1.4
Ensure only trusted container images are used (Manual)
Browse reusable Agent Skills, each with a clear purpose and practical guidance.
Ensure only trusted container images are used (Manual)
Ensure that Alpha clusters are not used for production workloads (Automated)
Consider GKE Sandbox for running untrusted workloads (Automated)
Enable Security Posture (Automated)
Ensure GKE clusters are not running using the Compute Engine default service account (Automated)
Prefer using dedicated GCP Service Accounts and Workload Identity (Manual)
Ensure Kubernetes Secrets are encrypted using keys managed in Cloud KMS (Automated)
Ensure the GKE Metadata Server is Enabled (Automated)
Ensure Container-Optimized OS (cos_containerd) is used for GKE node images (Automated)
Ensure Node Auto-Repair is enabled for GKE nodes (Automated)