Open lizrice opened 3 years ago
Before we get into implementation we should identify:
Based on the initial evaluation we should be able to decide whether a K8s controller patter is suitable for the integration or not. If yes, then which K8s API object we want to watch?
@danielpacak great points! Following the starboard documentation, if we choose to install using operator, we don't have the option of kube-hunter, the lifecycle will be the same as kube-bench. Both tools need to use in the case of new or update cluster processes. If these assumptions are correct, are kube-bench and kube-hunter a good case for operator use?
IMHO there's a difference between KubeBench and KubeHunter:
cluster
. Not having a native K8s resource that we can watch to trigger KubeHunter scans is the main challenge here.
@danielpacak what will be the steps? - Adding a kubehunterReport in pkg/operator/controller/ ?