Files
T
mukul975 c47eed6a64 Production hardening: security fixes, code quality, 724 skills complete
- Fix 25 shell=True subprocess calls with list-based commands
- Fix 49 verify=False in defensive skills (env-var override)
- Add timeout to 231 HTTP/subprocess/socket calls
- Fix 6 SQL injection patterns with whitelist validation
- Replace 8 __import__() with standard imports
- Remove 701 unused imports across 442 files
- Add authorized-testing disclaimers to all offensive skills
- Complete 11 incomplete skill directories
- Expand 10 stub SKILL.md files with full content
- Fix 2 YAML parse errors in frontmatter
- Fix 5 pre-existing syntax errors
- Convert 22 hardcoded paths/ports to environment variables
- Back up 21 redundant skill pairs to .bak
- Fix 2 global declaration errors
- 724/724 skills with full folder anatomy (SKILL.md + agent.py + api-reference.md + LICENSE)
- 0 compile errors across all 724 agent.py files
2026-03-19 13:26:49 +01:00

22 lines
1012 B
Markdown

# Standards and References - Kubernetes RBAC
## Kubernetes Documentation
- **RBAC Authorization**: https://kubernetes.io/docs/reference/access-authn-authz/rbac/
- **Authenticating**: https://kubernetes.io/docs/reference/access-authn-authz/authentication/
- **Audit Logging**: https://kubernetes.io/docs/tasks/debug/debug-cluster/audit/
## Security Benchmarks
- **CIS Kubernetes Benchmark**: Section 5.1 - RBAC and Service Accounts
- **NSA/CISA Kubernetes Hardening Guide**: https://media.defense.gov/2022/Aug/29/2003066362/-1/-1/0/CTR_KUBERNETES_HARDENING_GUIDANCE_1.2_20220829.PDF
## NIST Standards
- **NIST SP 800-53 Rev 5**: AC-2, AC-3, AC-5, AC-6, AU-3, AU-12
- **NIST SP 800-190**: Application Container Security Guide
## Tools
- **kubectl auth can-i**: Test RBAC permissions
- **rakkess**: Review access matrix for Kubernetes resources
- **rbac-lookup**: Find roles and bindings for users/groups
- **KubiScan**: Scan for risky RBAC configurations
- **kube-bench**: CIS benchmark checker for Kubernetes