mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-08-30 13:19:40 +03:00
Initial commit - 611 cybersecurity skills across all subdomains
This commit is contained in:
@@ -0,0 +1,28 @@
|
||||
# Standards - Pod Security Admission Controller
|
||||
|
||||
## Kubernetes Pod Security Standards
|
||||
|
||||
| Profile | Controls Enforced |
|
||||
|---------|------------------|
|
||||
| Baseline | No privileged, no hostPID/IPC/Network, no hostPorts, restricted volumes, no procMount, restricted seccomp, restricted capabilities |
|
||||
| Restricted | All Baseline + non-root, drop ALL caps, seccomp required, restricted volume types, no privilege escalation |
|
||||
|
||||
## CIS Kubernetes Benchmark v1.8
|
||||
- 5.2.1: Ensure privileged containers are not used
|
||||
- 5.2.2-5.2.4: Ensure host namespace sharing is disabled
|
||||
- 5.2.5: Ensure privilege escalation is not allowed
|
||||
- 5.2.6: Ensure root containers are not admitted
|
||||
- 5.2.7: Ensure seccomp profile is set
|
||||
- 5.7.3: Apply security context to pods
|
||||
|
||||
## NIST SP 800-190
|
||||
- Section 4.3: Container runtime security
|
||||
- Section 5.4: Admission control enforcement
|
||||
|
||||
## NSA/CISA Kubernetes Hardening Guide v1.2
|
||||
- Section 1: Pod Security - Use Pod Security Standards
|
||||
|
||||
## Compliance Mappings
|
||||
- PCI DSS v4.0 Req 2.2: Configuration standards
|
||||
- SOC 2 CC6.1: Logical access controls
|
||||
- HIPAA 164.312(a)(1): Access controls
|
||||
@@ -0,0 +1,38 @@
|
||||
# Workflow - Implementing Pod Security Admission
|
||||
|
||||
## Phase 1: Assessment
|
||||
1. List all namespaces and their current security posture
|
||||
2. Run dry-run against restricted profile for each namespace
|
||||
3. Document violations and required exemptions
|
||||
|
||||
## Phase 2: Apply Audit Mode
|
||||
```bash
|
||||
for ns in production staging; do
|
||||
kubectl label namespace $ns \
|
||||
pod-security.kubernetes.io/audit=restricted \
|
||||
pod-security.kubernetes.io/warn=restricted
|
||||
done
|
||||
```
|
||||
|
||||
## Phase 3: Fix Violations
|
||||
1. Update Deployments/StatefulSets with compliant security contexts
|
||||
2. Add seccomp profiles
|
||||
3. Switch containers to non-root
|
||||
4. Drop ALL capabilities
|
||||
|
||||
## Phase 4: Enable Enforcement
|
||||
```bash
|
||||
kubectl label namespace production \
|
||||
pod-security.kubernetes.io/enforce=restricted \
|
||||
pod-security.kubernetes.io/enforce-version=v1.28
|
||||
```
|
||||
|
||||
## Phase 5: Set Cluster Defaults
|
||||
1. Create AdmissionConfiguration with baseline defaults
|
||||
2. Apply to kube-apiserver
|
||||
3. Exempt system namespaces
|
||||
|
||||
## Phase 6: Monitor
|
||||
1. Watch for FailedCreate events
|
||||
2. Review audit logs weekly
|
||||
3. Update exemptions as needed
|
||||
Reference in New Issue
Block a user