A new ruleset should also be created for the Garden provider. This ruleset can be named Security Hardened Shoot Cluster which checks targeted Shoot resource by Project and Shoot name. The ruleset should reference DISA K8s STIG rules, which can be checked in the Shoot spec and also add additional rules.
What would you like to be added: A
Garden
provider that has access to the garden cluster can be implemented:A new ruleset should also be created for the
Garden
provider. This ruleset can be namedSecurity Hardened Shoot Cluster
which checks targetedShoot
resource byProject
andShoot
name. The ruleset should reference DISA K8s STIG rules, which can be checked in theShoot
spec and also add additional rules.[X] Add
Security Hardened Shoot Cluster
ruleset guide https://github.com/gardener/diki/pull/308[x] Implement rules
Update usage documentation:
Security Hardened Shoot Cluster
ruleset https://github.com/gardener/diki/pull/384