All authors
CyberStrikeus avatar

Claude Skills by CyberStrikeus

github.com/CyberStrikeus
1,315 skillsA× 1,256B× 57D× 20 installs318 views
Cis Ocp V180 4.2.1A

Activate Garbage collection in OpenShift Container Platform 4, as appropriate (Manual)

securitygobash
0
291
Cis Ocp V180 4.2.10A

Ensure that the --rotate-certificates argument is not set to false (Manual)

securitygobash
0
291
Cis Ocp V180 4.2.11A

Verify that the RotateKubeletServerCertificate argument is set to true (Manual)

securitygobash
0
291
Cis Ocp V180 4.2.12A

Ensure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)

securitygobash
0
291
Cis Ocp V180 4.2.2A

Ensure that the --anonymous-auth argument is set to false (Automated)

securitygobash
0
291
Cis Ocp V180 4.2.3A

Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)

securitygobash
0
291
Cis Ocp V180 4.2.4A

Ensure that the --client-ca-file argument is set as appropriate (Automated)

securityrustgo
0
291
Cis Ocp V180 4.2.5A

Verify that the read only port is not used or is set to 0 (Automated)

securitygobash
0
291
Cis Ocp V180 4.2.6A

Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)

securitygobash
0
291
Cis Ocp V180 4.2.7A

Ensure that the --make-iptables-util-chains argument is set to true (Manual)

securitygobash
0
291
Cis Ocp V180 4.2.8A

Ensure that the kubeAPIQPS [--event-qps] argument is set to 0 or a level which ensures appropriate event capture (Manual)

securitygobash
0
291
Cis Ocp V180 4.2.9A

Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)

securityrustgo
0
291
Cis Ocp V180 5.1.1A

Ensure cluster-admin role only used where required (Manual)

securitygobash
0
291
Cis Ocp V180 5.1.2A

Minimize access to secrets (Manual)

securitygobash
0
291
Cis Ocp V180 5.1.3A

Minimize wildcard use in Roles and ClusterRoles (Manual)

securitygobash
0
291
Cis Ocp V180 5.1.4A

Minimize access to create pods (Manual)

securitygobash
0
291
Cis Ocp V180 5.1.5A

Ensure default service accounts not actively used (Manual)

securitygokubernetes
0
291
Cis Ocp V180 5.1.6A

Ensure Service Account Tokens only mounted where necessary (Manual)

securitygobash
0
291
Cis Ocp V180 5.2.1A

Minimize admission of privileged containers (Manual)

securitygobash
0
291
Cis Ocp V180 5.2.10A

Minimize access to privileged Security Context Constraints (Manual)

securitygobash
0
291
Cis Ocp V180 5.2.2A

Minimize admission of containers sharing host process ID namespace (Manual)

securitygobash
0
291
Cis Ocp V180 5.2.3A

Minimize admission of containers sharing host IPC namespace (Manual)

securitygobash
0
291
Cis Ocp V180 5.2.4A

Minimize admission of containers sharing host network namespace (Manual)

securitygobash
0
291
Cis Ocp V180 5.2.5A

Minimize admission of containers with allowPrivilegeEscalation (Manual)

securitygobash
0
291
Cis Ocp V180 5.2.6A

Minimize admission of root containers (Manual)

securitygobash
0
291
Cis Ocp V180 5.2.7A

Minimize admission of containers with NET_RAW capability (Manual)

securityrustgo
0
291
Cis Ocp V180 5.2.8A

Minimize admission of containers with added capabilities (Manual)

securityrustgo
0
291
Cis Ocp V180 5.2.9A

Minimize admission of containers with capabilities assigned (Manual)

securityrustgo
0
291
Cis Ocp V180 5.3.1A

Ensure CNI in use supports Network Policies (Manual)

securitygonode
0
291
Cis Ocp V180 5.3.2A

Ensure all Namespaces have Network Policies defined (Manual)

securitygobash
0
291
Cis Ocp V180 5.4.1A

Prefer using secrets as files over secrets as environment variables (Manual)

securitygobash
0
291
Cis Ocp V180 5.4.2A

Consider external secret storage (Manual)

securitygokubernetes
0
291
Cis Ocp V180 5.5.1A

Configure Image Provenance using image controller configuration parameters (Manual)

securityrustgo
0
291
Cis Ocp V180 5.7.1A

Create administrative boundaries between resources using namespaces (Manual)

securitygobash
0
291
Cis Ocp V180 5.7.2A

Ensure seccomp profile set to docker/default in pod definitions (Manual)

securitygobash
0
291
Cis Ocp V180 5.7.3A

Apply Security Context to Your Pods and Containers (Manual)

securitygobash
0
291
Cis Ocp V180 5.7.4A

The default namespace should not be used (Manual)

securityrustgo
0
291
Cis Ocp V190 1.1.1A

Ensure that the API server pod specification file permissions are set to 600 or more restrictive (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.10A

Ensure that the Container Network Interface file ownership is set to root:root (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.11A

Ensure that the etcd data directory permissions are set to 700 or more restrictive (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.12A

Ensure that the etcd data directory ownership is set to root:root (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.13A

Ensure that the kubeconfig file permissions are set to 600 or more restrictive (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.14A

Ensure that the kubeconfig file ownership is set to root:root (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.15A

Ensure that the Scheduler kubeconfig file permissions are set to 600 or more restrictive (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.16A

Ensure that the Scheduler kubeconfig file ownership is set to root:root (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.17A

Ensure that the Controller Manager kubeconfig file permissions are set to 600 or more restrictive (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.18A

Ensure that the Controller Manager kubeconfig file ownership is set to root:root (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.19A

Ensure that the OpenShift PKI directory and file ownership is set to root:root (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.2A

Ensure that the API server pod specification file ownership is set to root:root (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.20A

Ensure that the OpenShift PKI certificate file permissions are set to 600 or more restrictive (Manual)

securitygobash
0
291