kube-linter
KubeLinter is a static analysis tool that checks Kubernetes YAML files and Helm charts to ensure the applications represented in them adhere to best practices.
파일 탐색기
최종 버전 다운로드 (.zip)- bug_report.md
- feature_request.md
- auto-merge.yaml
- build.yaml
- release.yaml
- CODEOWNERS
- dependabot.yaml
- release.yml
- kube-linter.go
- checks.md
- templates.md
- .nojekyll
- _coverpage.md
- _navbar.md
- _sidebar.md
- CNAME
- configuring-kubelinter.md
- custom_resource_template_test.go
- index.html
- README.md
- style.css
- using-kubelinter.md
- all-built-in-config.yaml
- cel-config.yaml
- forbidden-annotation-config.yaml
- kubeconform-config.yaml
- schema-validation-config.yaml
- statefulset-volumeclaimtemplate-annotation-config.yaml
- bats-support-clone.bash
- bats-tests.sh
- check-bats-tests.sh
- empty.go
- sanity_test.go
- .gitignore
- Dockerfile
- Dockerfile_alpine
- favicon.ico
- KubeLinter-horizontal.svg
- KubeLinter-vertical.svg
- consts.go
- default_checks.go
- default_test.go
- format.go
- enum.go
- pointers.go
- gen-string-generic.go
- consume.go
- default.go
- repeat.go
- split.go
- ternary.go
- ignore_error.go
- must.go
- version.go
- access-to-create-pods.yaml
- access-to-secrets.yaml
- cluster-admin-role-binding.yaml
- dangling-horizontalpodautoscaler.yaml
- dangling-ingress.yaml
- dangling-networkpolicy.yaml
- dangling-networkpolicypeer-podselector.yaml
- dangling-service.yaml
- dangling-servicemonitor.yaml
- default-service-account.yaml
- deprecated-service-account.yaml
- dnsconfig-options.yaml
- docker-sock.yaml
- drop-net-raw-capability.yaml
- duplicate-env-var.yaml
- env-var-secret.yaml
- env-var-value-from.yaml
- host-mounts.yaml
- hostipc.yaml
- hostnetwork.yaml
- hostpid.yaml
- hpa-minimum-replicas.yaml
- invalid-target-ports.yaml
- job-ttl-seconds-after-finished.yaml
- latest-tag.yaml
- liveness-port.yaml
- minimum-replicas.yaml
- mismatching-selector.yaml
- no-anti-affinity.yaml
- no-extensions-v1beta.yaml
- no-liveness-probe.yaml
- no-node-affinity.yaml
- no-readiness-probe.yaml
- no-rolling-update-strategy.yaml
- non-existent-service-account.yaml
- non-isolated-pod.yaml
- pdb-unhealthy-pod-eviction-policy.yaml
- pdbs-max-unavailable.yaml
- pdbs-min-available.yaml
- priority-class-name.yaml
- privilege-escalation.yaml
- privileged.yaml
- privilegedports.yaml
- read-only-root-fs.yaml
- read-secret-from-env-var.yaml
- readiness-port.yaml
- required-annotation-email.yaml
- required-label-owner.yaml
- restart-policy.yaml
- run-as-non-root.yaml
- scc-deny-privileged-container.yaml
- schema-validation.yaml
- servicetype.yaml
- sorted-keys.yaml
- ssh-port.yaml
- startup-port.yaml
- sysctls.yaml
- unsafe-proc-mount.yaml
- unset-cpu-requirements.yaml
- unset-memory-requirements.yaml
- usenamespace.yaml
- wildcard-use-in-rules.yaml
- writable-host-mount.yaml
- built_in_checks.go
- built_in_checks_test.go
- parameter_desc.go
- template.go
- check_registry.go
- command.go
- format_wrapper.go
- template.go
- template_test.go
- invalid.yaml
- valid-pod.yaml
- command.go
- command_test.go
- format_output.go
- format_output_test.go
- output.go
- output_test.go
- sarif_format.go
- command.go
- command_test.go
- command.go
- command.go
- parse.go
- check.go
- config.go
- flags.go
- gen.go
- config_resolver.go
- config_resolver_test.go
- condition_types.go
- groupversion_info.go
- gvkr_types.go
- identifier.go
- scaledjob_types.go
- scaledobject_types.go
- scaletriggers_types.go
- triggerauthentication_types.go
- zz_generated.deepcopy.go
- diagnostic.go
- pod_spec.go
- gvk.go
- hpa_spec.go
- job_spec.go
- metadata.go
- pod_spec.go
- scc_spec.go
- sts_spec.go
- sts_spec_test.go
- update_strategy.go
- ignore.go
- ignore_test.go
- instantiated_check.go
- object.go
- clusterrole.go
- clusterrolebinding.go
- container.go
- context.go
- cronjob.go
- horizontalpodautoscaler.go
- ingress.go
- job.go
- networkpolicy.go
- pod.go
- role.go
- rolebinding.go
- scaledobject.go
- scc.go
- service.go
- servicemonitor.go
- context.go
- create_contexts.go
- create_contexts_test.go
- parse_yaml.go
- parse_yaml_test.go
- string.go
- any.go
- clusterrole.go
- clusterrolebinding.go
- cronjob.go
- daemonset.go
- deployment.go
- deployment_like.go
- deploymentconfig.go
- horizontalpodautoscaler.go
- ingress.go
- job.go
- job_like.go
- networkpolicy.go
- pod.go
- poddisruptionbudget.go
- pvc.go
- pvc_test.go
- registry.go
- replicaset.go
- replicationcontroller.go
- role.go
- rolebinding.go
- scaledobject.go
- securitycontext.go
- service.go
- serviceaccount.go
- serviceMonitor.go
- statefulset.go
- types.go
- path.go
- run.go
- gen-params.go
- params.go
- template.go
- template_test.go
- all.go
- all_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- main.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- params_test.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- demonset.yaml
- schema.json
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- all-sorted-complex.yaml
- complex-pod-spec.yaml
- complex-service.yaml
- configmap-merge-unsorted.yaml
- configmap-unsorted-data.yaml
- container-with-merge.yaml
- deeply-nested-unsorted.yaml
- edge-cases.yaml
- mixed-sorting.yaml
- multi-container.yaml
- non-recursive.yaml
- numeric-keys.yaml
- reused-labels-sorted.yaml
- reused-labels-unsorted.yaml
- sorted-deployment.yaml
- unsorted-nested.yaml
- unsorted-top-level.yaml
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- template_test.go
- check_probe_port.go
- forbidden_matcher.go
- forbiden_matcher_test.go
- json.go
- map_structure.go
- per_container_check.go
- required_matcher.go
- required_matcher_test.go
- value_in_range.go
- value_in_range_test.go
- gen-params.go
- gen-params_test.go
- params.go
- template.go
- template_test.go
- gen-params.go
- params.go
- template.go
- gen-params.go
- params.go
- template.go
- gen.go
- registry.go
- templates_testutils.go
- kube-lint-config.json
- sarif-schema-2.1.0.json
- access-to-create-pods.yml
- access-to-secrets.yml
- cel.yml
- cluster-admin-role-binding.yml
- dangling-hpa.yml
- dangling-ingress.yml
- dangling-networkpolicy.yml
- dangling-networkpolicypeer-podselector.yml
- dangling-service.yml
- dangling-servicemonitor.yml
- default-service-account.yml
- deprecated-service-account-field.yml
- dnsconfig-options-ndots.yml
- docker-sock.yml
- drop-net-raw-capability.yml
- duplicate-env-var.yaml
- env-var-secret.yml
- env-var-value-from.yml
- exposed-services.yml
- forbidden-annotation.yml
- host-ipc.yml
- host-network.yml
- host-pid.yml
- hpa-minimum-three-replicas.yml
- invalid-target-ports.yaml
- job-ttl-seconds-after-finished.yaml
- kubeconform.yml
- latest-tag.yml
- liveness-port.yml
- minimum-three-replicas.yml
- mismatching-selector.yml
- no-anti-affinity.yml
- no-extensions-v1beta.yml
- no-liveness-probe.yml
- no-node-affinity.yml
- no-read-only-root-fs.yml
- no-readiness-probe.yml
- no-rolling-update-strategy.yml
- non-existent-service-account.yml
- non-isolated-pod.yml
- pdb-max-unavailable.yaml
- pdb-min-available.yaml
- pdb-unhealthy-pod-eviction-policy.yaml
- priority-class-name.yaml
- privilege-escalation-container.yml
- privileged-container.yml
- privileged-ports.yml
- read-secret-from-env-var.yml
- readiness-port.yml
- required-annotation-email.yml
- required-label-owner.yml
- restart-policy.yaml
- run-as-non-root.yml
- scc-deny-privileged-container.yml
- sensitive-host-mounts.yml
- sorted-keys.yaml
- ssh-port.yml
- startup-port.yml
- statefulset-volumeclaimtemplate-annotation.yml
- unsafe-proc-mount.yml
- unsafe-sysctls.yml
- unset-cpu-requirements.yml
- unset-memory-requirements.yml
- use-namespace.yml
- wildcard-in-rules.yml
- writable-host-mount.yml
- Chart.yaml
- values.yaml
- configmap.yaml
- Chart.yaml
- values.yaml
- subchart-0.1.0.tgz
- test-connection.yaml
- _helpers.tpl
- deployment.yaml
- hpa.yaml
- ingress.yaml
- NOTES.txt
- service.yaml
- serviceaccount.yaml
- .helmignore
- Chart.lock
- Chart.yaml
- values.yaml
- deployment.yaml
- service.yaml
- kustomization.yaml
- deployment.yaml
- service.yaml
- kustomization.yaml
- deployment.yaml
- .helmignore
- Chart.yaml
- values.yaml
- mychart-0.1.0.tgz
- splunk.yaml
- empty.go
- go.mod
- go.sum
- tools.go
- empty.go
- go.mod
- go.sum
- tools.go
- .gitignore
- .golangci.yml
- .goreleaser.yaml
- .pre-commit-hooks.yaml
- CODE_OF_CONDUCT.md
- config.yaml.example
- CONTRIBUTING.md
- go.mod
- go.sum
- kubelinter-cosign.pub
- LICENSE
- Makefile
- README.md
- RELEASE.md
- SECURITY.md
# 설치 가이드
git clone https://github.com/stackrox/kube-linter
깃허브에서 프로젝트 코드 전체를 내 컴퓨터로 내려받습니다.
cd kube-linter
방금 내려받은 프로젝트 폴더 안으로 이동합니다.
2. 공식 설치 스크립트
쉬움 추천go install golang.stackrox.io/kube-linter/cmd/kube-linter@latest
지정된 버전을 바로 다운로드해서 설치합니다. 레포를 직접 클론할 필요가 없습니다.
brew install kube-linter
Homebrew로 이미 빌드된 패키지를 바로 설치합니다. 소스 빌드가 필요 없습니다.
이 레포의 README에 적힌 실제 명령어를 그대로 가져왔습니다.
3. Docker
쉬움- Git GitHub에서 프로젝트 코드를 내려받으려면 필요합니다.
- Docker Desktop 컨테이너를 빌드하고 실행하려면 필요합니다. 설치 후 실행해서 백그라운드에 켜두세요.
docker pull stackrox/kube-linter:latest
이 명령어를 터미널에 그대로 입력해 실행하세요.
이 레포의 README에 적힌 실제 명령어를 그대로 가져왔습니다.
4. Go
보통go install golang.stackrox.io/kube-linter/cmd/kube-linter@latest
지정된 버전을 바로 다운로드해서 설치합니다. 레포를 직접 클론할 필요가 없습니다.
이 레포의 README에 적힌 실제 명령어를 그대로 가져왔습니다.
5. Make
보통- Git GitHub에서 프로젝트 코드를 내려받으려면 필요합니다.
- Make Linux/macOS는 보통 기본 설치되어 있습니다. Windows는 별도 설치(예: MSYS2, WSL)가 필요합니다.
make build
생성된 빌드 설정을 바탕으로 실제 컴파일을 진행해 실행 파일을 만듭니다.
make test
생성된 빌드 설정을 바탕으로 실제 컴파일을 진행해 실행 파일을 만듭니다.
make e2e-test
생성된 빌드 설정을 바탕으로 실제 컴파일을 진행해 실행 파일을 만듭니다.
make e2e-bats
생성된 빌드 설정을 바탕으로 실제 컴파일을 진행해 실행 파일을 만듭니다.
이 레포의 README에 적힌 실제 명령어를 그대로 가져왔습니다.
