kubernetes / k8s.io

Code and configuration to manage Kubernetes project infrastructure, including various *.k8s.io sites
https://git.k8s.io/community/sig-k8s-infra
Apache License 2.0
712 stars 794 forks source link

Harden EKS/GKE Clusters #5110

Open upodroid opened 1 year ago

upodroid commented 1 year ago

Our build clusters run untrusted code and we should try to harden the cluster configuration and the pod configuration.

Kubernetes Best Practices:

GKE Best Practices:

EKS Best Practices:

upodroid commented 1 year ago

/area infra /area infra/aws /area infra/gcp /priority important-soon

xmudrii commented 1 year ago

EKS-related IAM improvements are tracked as part of #5160

k8s-triage-robot commented 7 months ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

xmudrii commented 7 months ago

/remove-lifecycle stale

k8s-triage-robot commented 4 months ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

xmudrii commented 4 months ago

/remove-lifecycle stale

k8s-triage-robot commented 1 month ago

The Kubernetes project currently lacks enough contributors to adequately respond to all issues.

This bot triages un-triaged issues according to the following rules:

You can:

Please send feedback to sig-contributor-experience at kubernetes/community.

/lifecycle stale

xmudrii commented 1 month ago

/remove-lifecycle stale