11 ms·
Kubescape – tool for testing if Kubernetes is deployed securely
- jkaftzan 5y agoKubescape is The first open-source tool for testing if Kubernetes is deployed securely as defined in the Kubernetes Hardening Guidance by NSA and CISA
- _kec6 5y agoSomething about the capitalization in this comment + the above scares me somehow.
- jkaftzan 5y agonot sure i understand, can you explain?
- alvarlagerlof 5y agoMaybe "The" being capitalized.
- imw 5y agoMay I introduce you to my friend and colleague, Hardening Guidance?
- gravypod 5y agoI love that since Kube is a standard API we can implement preflight checks like this that work for "any" kube cluster automatically.
- jkaftzan 5y agocool! happy to hear that. if you have any ideas or comments about Kubescape, we would love to hear them
- gravypod 5y agoIf you could check for container signing and providence on all materials and make sure that only a single registry is being used (ex only `internal.company.com:443`) and make sure it's not possible to schedule pods with unsigned/untrusted containers that would be awesome.
- eris_agx 5y agoFor materials you can use syft https://github.com/anchore/syft https://github.com/anchore/syft
- jkaftzan 5y agointeresting, I'll send that to our dev team. BTW - you can suggest these things on Kubescape page @ Github and see status etc.
- deleted 5y ago[deleted]
- leeoniya 5y agos/providence/provenance
- dwertent 5y agoYes, we are working on integration with anchore :)
- torgard 5y agoThis couldn't have come at a better time! I have to do a report on hardening and such of our infrastructure next week. Great!
- jkaftzan 5y agoexcellent, good luck! let me know if you need any help
- zxspectrum1982 5y agoHow is this different from auditing and hardening your Kubernetes nodes with OpenSCAP data streams (AKA "profiles")?
- anotherhue 5y agoI politely suggest that a security focused tool should not further the curl|bash pattern.
- geofft 5y agoWhat alternative pattern would you suggest?
- anotherhue 5y agobinary packages, maybe through github releases. debian packages, potentially upstreamed into the package repos (though that's some effort). It's quite presumptive to presume to know how a target system is to be configured. no matter which alternative, curl|bash is security risk enough to never use: https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-bash-server-side/ https://www.idontplaydarts.com/2016/04/detecting-curl-pipe-b... gpg can help (below from zerotier): curl -s 'https://raw.githubusercontent.com/zerotier/ZeroTierOne/master/doc/contact%40zerotier.com.gpg https://raw.githubusercontent.com/zerotier/ZeroTierOne/maste...' | gpg --import && \ if z=$(curl -s 'https://install.zerotier.com/ https://install.zerotier.com/' | gpg); then echo "$z" | sudo bash; fi
- geofft 5y agoWhat's the advantage of binary packages through GitHub releases? How do you audit them? I'm aware of the fact that you can detect curl | bash server-side, and it's a neat trick, but I don't understand the security risk of it. The server is supplying you with arbitrary content that you're not auditing - what does it matter if it supplies you different arbitrary content? What's the advantage of the GPG approach? Last I checked, the GPG command was capable of signing malicious binaries. I do agree about the configuration argument. But that's not a security argument.
- anotherhue 5y agoI think you may be conflating the application owner and the delivery system. If we're installing the application I think we're implicitly trusting the author. If you copy/paste http instead of https then you've given execution control to every single middlebox along the way. If the code is hosted on an evil sourceforge, then you've given them execution control. deb packages will do signature checks, any many authors will list checksums in their releases which we can use to verify.
- sdze 5y agoKubernetes? God forbid! Very few companies have mastered this technology, and frankly, no one needs it. That such a testing tool is necessary confirms my assumption. Security is now outsourced.
- lolthishuman 5y agoSecurity has been outsourced ever since hardware.
- glitchcrab 5y agoSo if I were to make a daft assumption that frankly, no one needs DNS, and then the NSA were to bring out a DNS infra hardening guide then I would also be correct? Your comment is nonsense.
- goodpoint 5y agoUnfortunately on HN unnecessary complexity is workshipped.
- domnomnom 5y agoIs security a zero sum game?
- whatshisface 5y agoIt's negative sum overall because it takes smart people away from other things.
- pyuser583 5y agoThis made me laugh
- ButterWashed 5y agoDoes the NSA/CISA advice differ significantly from CIS? KubeBench does a great job of CIS assessment.
- lsandler 5y agoCIS is very prescriptive. It gives you a list of very specific checks with very little context. NSA, on the other hand, explains the problems and potential attack vectors allowing you to adjust and extend the checks to your specific needs.
- chmod-777 5y agoThere is also an implementation difference between the two, while KubeBench requires installation within the cluster, Kubescape runs as CLI from any computer using Kube API, so it can be added to any CI/CD pipeline very easily, also the latest version enables you to scan YAML files before you deploy them so you know early on whether you are compliant.
- raesene9 5y agoThe NSA doesn't really do a full coverage of Kubernetes security hardening, but does touch on a lot of the same ground as the CIS benchmark. It also covers some areas that aren't in-scope of the CIS benchmark, at a high level.
- j03b 5y agoThis tool is great! Ran through all these checks and deployed them to our cluster the other day. Immutable fs & non-root is easier than I thought to deploy with k8s, going to be looking into privilege drops this week too.
- jkaftzan 5y agothanks a lot! let us know if you have any comments or ideas
- kgarten 5y agoThere's CIS KubeBench and OpenSCAP as other comments mentioned. I don't trust an organization that keeps Zero days to themselves for offensive capabilities.
- lallysingh 5y agoThey just made a list of things to check for. Use more than one checklist to get the best coverage.
- kgarten 5y agoIt's not a list, I won't be executing a shell script from a organization that cares about having zero day exploits.
- lallysingh 5y agoThe linked repo isn't from the NSA, it's from armosec. Who, afaict, don't have zero days in their possession.
- kgarten 5y agoSorry misread ... You are right. Still, I will not execute a shell script from a github repository to find security issues ...
- bsdnoob 5y agowhy will you not if you can read the script?
- kgarten 5y agothe script downloads a binary blob and copies it into your bin folder. no hash check ... If somebody can replace the binary blob, there's no security check before I would execute it. do you know that you get the right binary blob? If you use that to increase your security, ...
- ewg4345h43 5y agoKubernetes is way too overengineered. It should be as simple as docker compose. and Kubernetes also added StatefulSets for things like database, but all kubernetes gurus don't recommend to use it in Cloud, but use databases provided by the cloud providers :facepalm because, well, it's too complicated...
- lsandler 5y agoAny universal platform or toolkit is overengineered somewhat (or a lot), but this is the name of the game. Flexibility comes at the price forcing you to invest into configuration, automation, deployment and maintenance. Then security comes to close the gaps. Every player in this game is honestly trying to be better and help others. Kubernetes is a fact of life and rightfully so. It needs helper tools in several areas. Security is just one of them and Kubescape is just a one step of many...
- deleted 5y ago[deleted]
- asjfj9 5y agoI feel like installing a security tool by curling a random script off the internet and piping it into `/bin/bash` is a bit contradictory. Surely there's a better way to install this?
- capableweb 5y agoIf you're smart enough to realize that there might be something to worry about, you should be smart enough to be able to figure out how to divide the command into three parts instead of one (download the script, inspect the contents and then run the same inspected [local] script). Every time a project with curl | sh is featured on HN this comes up. At this point we might as well write a bot that scrapes submitted pages for "curl * | * (sh|bash)" and leave this comment for all of them.
- uzakov 5y ago> If you're smart enough to realize that there might be something to worry about, you should be smart enough to be able to figure out how to This is gatekeeping 101. Some people are just starting out in security/software engineering and things like this might not be obvious to them. It's good that you have suggested what to do but there are different ways to "suggest" things.
- kovek 5y agoSo ‘curl; cat; bash’ and not ‘curl | sh’ because the server can detect the pace/existence of the pipe and sneak in some unsafe commands.
- capableweb 5y ago> This is gatekeeping 101 What? How? > Some people are just starting out in security/software engineering and things like this might not be obvious to them That's fair enough. But I wished these beginners then didn't make claims like "security tools cannot be installed like this, it's insecure", and we would all be better off. Either you know what you're talking about and you share your knowledge. Or, you listen and ask questions in order to eventually know what you're talking about.
- deleted 5y ago[deleted]
- sheerun 5y agoAnd hacking it on the occasion
- deleted 5y ago[deleted]
- chmod-777 5y agoI see a lot of questions here about CIS and other frameworks, Kubescape put out a survey to ask what framework would be most beneficial next, you can impact it here: https://docs.google.com/forms/d/1ZitQztCQ3xHFQnywUerPj3LmjmXKHfdgs9T1Evs1gXI/viewform?edit_requested=true https://docs.google.com/forms/d/1ZitQztCQ3xHFQnywUerPj3LmjmX...
- jkaftzan 5y agoWe are continuing to work on Kubescape and enhance it with more features and capabilities: Kubescape can now check that YAML files and HELM charts are configured correctly as defined by NSA and CISA guidance. No cluster is required and you can scan for misconfigurations as early as when devs are submitting the K8s manifest files. Kubescape supports new output formats like json and junit xml. You can integrate Kubescape results output to any devops tool like Jenkins, CricleCI, Github workflows. If you haven’t checked it out yet, what are you waiting for? https://github.com/armosec/kubescape/ https://github.com/armosec/kubescape/