SovereignCloudStack / standards

SCS standards in a machine readable format
https://scs.community/
Creative Commons Attribution Share Alike 4.0 International
34 stars 23 forks source link

Kubernetes cluster hardening standard (previously "K8s cluster baseline security") #581

Closed cah-hbaum closed 3 months ago

cah-hbaum commented 5 months ago

The "Baseline K8s cluster security" was created previously. In the PR (https://github.com/SovereignCloudStack/standards/pull/376) there were some discussions about the structure and overall usefulness of the standard. This issue should adapt the standard (since it is still in the draft phase) in order to better adhere to the requirements brought forward. The standard was also retitled to "Kubernetes cluster hardening".

cah-hbaum commented 4 months ago

Rebased the branch.

cah-hbaum commented 3 months ago

Sorry, I totally missed the section "Standard". Okay, so we have a succinct list. I think we can drop the introductory paragraph from that section, but I would add a remark somewhere in the beginning of the "Hardening Kubernetes" paragraph that "Hardening Kubernetes" is not authoritative, and that the "Standards" section contains the authoritative part.

Updated the paragraphs just as mentioned by @mbuechse Also did some rebasing to remove the merge conflicts

mbuechse commented 3 months ago

This is ready to merge. I trust that you did what you said. So I won't review it now. You can proceed.

cah-hbaum commented 3 months ago

Merging!