kubesec
Security risk analysis for Kubernetes resources
File Explorer
Download Latest Version (.zip)- bug_report.yaml
- config.yml
- feature_request.yaml
- lint_bash.yml
- lint_docker.yml
- lint_go.yml
- lint_yml.yml
- move_issues_to_board.yml
- release.yml
- release_containers.yml
- release_containers_webhook.yml
- security_analysis.yml
- test_acceptance.yml
- test_unit.yml
- dependabot.yml
- PULL_REQUEST_TEMPLATE.md
- http.go
- main.go
- print-rules.go
- scan.go
- version.go
- kubesec-demo.gif
- table-output.png
- writer.go
- report.go
- rule.go
- rule_test.go
- ruleset.go
- ruleset_test.go
- schema.go
- schema_test.go
- allowPrivilegeEscalation.go
- allowPrivilegeEscalation_test.go
- apparmorAny.go
- apparmorAny_test.go
- apparmorTestCases.go
- apparmorUnconfined.go
- apparmorUnconfined_test.go
- automountServiceAccountToken.go
- automountServiceAccountToken_test.go
- bindingsToSystemAnonymous.go
- bindingsToSystemAnonymous_test.go
- capDropAll.go
- capDropAll_test.go
- capDropAny.go
- capDropAny_test.go
- capSysAdmin.go
- capSysAdmin_test.go
- dockerSock.go
- dockerSock_test.go
- helper.go
- helper_test.go
- hostAliases.go
- hostAliases_test.go
- hostIPC.go
- hostIPC_test.go
- hostNetwork.go
- hostNetwork_test.go
- hostPID.go
- hostPID_test.go
- hostUsers.go
- hostUsers_test.go
- limitsCPU.go
- limitsCPU_test.go
- limitsMemory.go
- limitsMemory_test.go
- privileged.go
- privileged_test.go
- procMount.go
- procMount_test.go
- readOnlyRootFilesystem.go
- readOnlyRootFilesystem_test.go
- requestsCPU.go
- requestsCPU_test.go
- requestsMemory.go
- requestsMemory_test.go
- runAsGroup.go
- runAsGroup_test.go
- runAsNonRoot.go
- runAsNonRoot_test.go
- runAsUser.go
- runAsUser_test.go
- seccompAny.go
- seccompAny_test.go
- seccompTestCases.go
- seccompUnconfined.go
- seccompUnconfined_test.go
- secretsAsEnvironmentVariables.go
- secretsAsEnvironmentVariables_test.go
- selector.go
- serviceAccountName.go
- serviceAccountName_test.go
- volumeClaimAccessModeReadWriteOnce.go
- volumeClaimAccessModeReadWriteOnce_test.go
- volumeClaimRequestsStorage.go
- volumeClaimRequestsStorage_test.go
- server.go
- util.go
- util_test.go
- sarif.tpl
- carts-db-dep.yaml
- carts-dep.yaml
- catalogue-db-dep.yaml
- catalogue-dep.yaml
- front-end-dep.yaml
- loadtest-dep.yaml
- orders-db-dep.yaml
- orders-dep.yaml
- payment-dep.yaml
- queue-master-dep.yaml
- rabbitmq-dep.yaml
- session-db-dep.yaml
- shipping-dep.yaml
- user-db-dep.yaml
- user-dep.yaml
- score-0-daemonset-v1.11.yml
- score-0-statefulset-v1.11.yml
- allowPrivilegeEscalation.yaml
- bug-dump-2.json
- critical-double-multiple.yml
- critical-double.yml
- empty-file
- empty-json-file
- form-prefix-file.json
- form-prefix-file.yml
- form-prefix-not-file.json
- form-prefix-not-file.yml
- invalid-input-pod-dump.json
- invalid-schema.yml
- invalid-type.yml
- multi.yml
- score-0-cap-chown.yml
- score-0-cap-sys-admin-and-cap-chown.yml
- score-0-cap-sys-admin.yml
- score-0-daemonset-host-network.yml
- score-0-daemonset-host-pid.yml
- score-0-daemonset-mount-docker-socket.yml
- score-0-daemonset-securitycontext-privileged.yml
- score-0-daemonset-volume-host-docker-socket.yml
- score-0-dep-apparmor-empty-securitycontext.yml
- score-0-dep-apparmor-unconfined-container.yml
- score-0-dep-apparmor-unconfined-ephemeralcontainer.yml
- score-0-dep-apparmor-unconfined-initcontainer.yml
- score-0-dep-apparmor-unconfined-spec-securitycontext.yml
- score-0-dep-seccomp-empty-securitycontext.yml
- score-0-dep-seccomp-unconfined-container.yml
- score-0-dep-seccomp-unconfined-ephemeralcontainer.yml
- score-0-dep-seccomp-unconfined-initcontainer.yml
- score-0-dep-seccomp-unconfined-spec-securitycontext.yml
- score-0-podsecuritypolicy-permissive.yml
- score-0-statefulset-no-sec.yml
- score-1-cap-drop-all.yml
- score-1-daemonset-default.yml
- score-1-dep-apparmor-nonunconfined-container.yml
- score-1-dep-apparmor-nonunconfined-ephemeralcontainer.yml
- score-1-dep-apparmor-nonunconfined-initcontainer.yml
- score-1-dep-apparmor-nonunconfined-spec-securitycontext.yml
- score-1-dep-default.yml
- score-1-dep-empty-security-context.yml
- score-1-dep-invalid-security-context.yml
- score-1-dep-podseccon-run-as-group-1.yml
- score-1-dep-podseccon-run-as-group-10001.yml
- score-1-dep-podseccon-run-as-non-root.yml
- score-1-dep-podseccon-run-as-user-1.yml
- score-1-dep-podseccon-run-as-user-10001.yml
- score-1-dep-resource-limit-cpu.yml
- score-1-dep-resource-limit-memory.yml
- score-1-dep-ro-root-fs.yml
- score-1-dep-seccomp-nonunconfined-container.yml
- score-1-dep-seccomp-nonunconfined-ephemeralcontainer.yml
- score-1-dep-seccomp-nonunconfined-initcontainer.yml
- score-1-dep-seccomp-nonunconfined-spec-securitycontext.yml
- score-1-dep-seccon-run-as-group-1.yml
- score-1-dep-seccon-run-as-group-10001.yml
- score-1-dep-seccon-run-as-non-root.yml
- score-1-dep-seccon-run-as-user-1.yml
- score-1-dep-seccon-run-as-user-10001.yml
- score-1-pod-automount-sa-set-to-false.yml
- score-1-pod-automountservicetoken.yml
- score-1-pod-default.yml
- score-1-pod-hostUsers-set-to-false.yml
- score-1-prod-dump.yaml
- score-1-statefulset-default.yml
- score-1-statefulset-novolumeclaimtemplate.yml
- score-1-statefulset-volumeclaimtemplate.yml
- score-2-dep-serviceaccount.yml
- score-2-pod-serviceaccount.yml
- score-5-pod-serviceaccount.yml
- very-long-file
- bats
- bats-assert
- bats-support
- 0_test_deps.bats
- 1_cli.bats
- 2_regression.bats
- 3_todo.bats
- _helper.bash
- .deepsource.toml
- .dockerignore
- .editorconfig
- .gitignore
- .gitmodules
- .goreleaser.yml
- .hadolint.yaml
- .markdownlint.yaml
- .yamllint.yaml
- CHANGELOG.md
- cloudbuild.yaml
- CODE_OF_CONDUCT.md
- CONTRIBUTING.md
- Dockerfile
- Dockerfile.scratch
- go.mod
- go.sum
- LICENSE
- main.go
- MAINTAINERS
- Makefile
- README.md
- SECURITY.md
# Installation Guide
1. Get the code
git clone https://github.com/controlplaneio/kubesec
Downloads the entire project code from GitHub to your computer.
cd kubesec
Moves into the project folder you just downloaded.
2. Docker
Easy RecommendedPrerequisites
- Git Needed to download the project code from GitHub.
- Docker Desktop Needed to build and run containers. Install it and keep it running in the background.
docker run -i kubesec/kubesec:v2 scan /dev/stdin < kubesec-test.yaml
Runs the built image as an actual container.
docker run -d -p 8080:8080 kubesec/kubesec:v2 http 8080
Runs the built image as an actual container.
- [Docker Usage](#docker-usage)
Type this command into your terminal and run it.
Run docker compose ps to check the containers are Up. If the README mentions a port, open http://localhost:PORT in your browser.
Pulled directly from this repo's README.
3. Go
MediumPrerequisites
$ go install github.com/controlplaneio/kubesec/v2@latest
Type this command into your terminal and run it.
If the build finishes without errors, it worked. If you used go run ., check the terminal output.
Pulled directly from this repo's README.
4. Make
MediumPrerequisites
- Git Needed to download the project code from GitHub.
- Make Usually pre-installed on Linux/macOS. On Windows, install separately (e.g. via MSYS2 or WSL).
make
Compiles the code based on the generated build configuration to produce an executable.
If it finishes without errors, it worked. Try running the generated executable directly.
// repository documentation
Was this content helpful?
(0 ratings)
