4 ms·
Re: scanning of images, if you're using Google Container Registry (or Google Artifact Registry) there's also Artifact Analysis and Vulnerability scanning which
by cipherself 3y ago
Re: scanning of images, if you're using Google Container Registry (or Google Artifact Registry) there's also Artifact Analysis and Vulnerability scanning which you can turn on (and pay for)[0]
Re: security, defining security contexts for containers and pods are quite important, the container should not run as root, you should drop all capabilities, ...etc. For example
securityContext:
runAsNonRoot: true
runAsGroup: 1000
runAsUser: 1000
privileged: false
allowPrivilegeEscalation: false
readOnlyRootFilesystem: true
capabilities:
drop:
- ALL
You should also use something like kubescape[1] to regularly scan your cluster (or helm files or yaml files). Furthermore, you should use an admission controller[2] like Gatekeeper[3] to enforce certain policies in your clusters e.g. containers should always have a securityContext.
[0] https://cloud.google.com/artifact-registry/docs/analysis https://cloud.google.com/artifact-registry/docs/analysis
[1] https://github.com/kubescape/kubescape https://github.com/kubescape/kubescape
[2] https://kubernetes.io/docs/reference/access-authn-authz/admission-controllers/ https://kubernetes.io/docs/reference/access-authn-authz/admi...
[3] https://github.com/open-policy-agent/gatekeeper https://github.com/open-policy-agent/gatekeeper