k8sstormcenter / honeycluster

Threat-informed defense for cloudnative: Reference Implementation of a so-called Honeycluster - for kind (and GKE, RKE2, AKS)
Apache License 2.0
19 stars 2 forks source link

RedPanda hardening #9

Open entlein opened 6 months ago

entlein commented 6 months ago

The current redpanda deployment is insecure, with unauthenticated clients. The redpanda/(rke2)values.yaml should be reviewed and altered such that the default settings are acceptable from a security first standpoint, as long as this doesn't not lead to a massively more complicated setup.

pjoomen commented 6 months ago

I plan on looking into the redpanda deployment in the coming days.

entlein commented 2 months ago

At KCD Munich we learnt of a way we can avoid red-panda, which I d much prefer since it is the heaviest piece at the moment. So I suspect it will be deprecated at some soonish point