mirror of
https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git
synced 2026-06-15 23:44:56 +03:00
708 B
708 B
Workflows - RBAC Hardening
Hardening Workflow
- Audit all existing ClusterRoleBindings and RoleBindings
- Identify overprivileged accounts (cluster-admin sprawl)
- Create namespace-scoped Roles with minimum required permissions
- Migrate workloads to dedicated service accounts
- Disable automountServiceAccountToken on default service accounts
- Integrate OIDC for user authentication
- Deploy RBAC monitoring and alerting
- Schedule quarterly RBAC reviews
Continuous Compliance
- Weekly: automated RBAC audit with rbac-lookup
- Monthly: review new RoleBindings created in past 30 days
- Quarterly: full access review with stakeholder sign-off
- Annually: penetration test RBAC boundaries