Initial commit - 611 cybersecurity skills across all subdomains

This commit is contained in:
mukul975
2026-02-25 10:47:44 +01:00
commit 22a7ab1462
1765 changed files with 280648 additions and 0 deletions
@@ -0,0 +1,28 @@
# Standards - Pod Security Admission Controller
## Kubernetes Pod Security Standards
| Profile | Controls Enforced |
|---------|------------------|
| Baseline | No privileged, no hostPID/IPC/Network, no hostPorts, restricted volumes, no procMount, restricted seccomp, restricted capabilities |
| Restricted | All Baseline + non-root, drop ALL caps, seccomp required, restricted volume types, no privilege escalation |
## CIS Kubernetes Benchmark v1.8
- 5.2.1: Ensure privileged containers are not used
- 5.2.2-5.2.4: Ensure host namespace sharing is disabled
- 5.2.5: Ensure privilege escalation is not allowed
- 5.2.6: Ensure root containers are not admitted
- 5.2.7: Ensure seccomp profile is set
- 5.7.3: Apply security context to pods
## NIST SP 800-190
- Section 4.3: Container runtime security
- Section 5.4: Admission control enforcement
## NSA/CISA Kubernetes Hardening Guide v1.2
- Section 1: Pod Security - Use Pod Security Standards
## Compliance Mappings
- PCI DSS v4.0 Req 2.2: Configuration standards
- SOC 2 CC6.1: Logical access controls
- HIPAA 164.312(a)(1): Access controls
@@ -0,0 +1,38 @@
# Workflow - Implementing Pod Security Admission
## Phase 1: Assessment
1. List all namespaces and their current security posture
2. Run dry-run against restricted profile for each namespace
3. Document violations and required exemptions
## Phase 2: Apply Audit Mode
```bash
for ns in production staging; do
kubectl label namespace $ns \
pod-security.kubernetes.io/audit=restricted \
pod-security.kubernetes.io/warn=restricted
done
```
## Phase 3: Fix Violations
1. Update Deployments/StatefulSets with compliant security contexts
2. Add seccomp profiles
3. Switch containers to non-root
4. Drop ALL capabilities
## Phase 4: Enable Enforcement
```bash
kubectl label namespace production \
pod-security.kubernetes.io/enforce=restricted \
pod-security.kubernetes.io/enforce-version=v1.28
```
## Phase 5: Set Cluster Defaults
1. Create AdmissionConfiguration with baseline defaults
2. Apply to kube-apiserver
3. Exempt system namespaces
## Phase 6: Monitor
1. Watch for FailedCreate events
2. Review audit logs weekly
3. Update exemptions as needed