All authors

Claude Skills by CyberStrikeus
github.com/CyberStrikeus7,689 skills0 installs16,544 views
- Cis Ocp V160 1.2.4Use https for kubelet connections (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 1.2.5Ensure that the kubelet uses certificates to authenticate (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 1.2.6Verify that the kubelet certificate authority is set as appropriate (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 1.2.7Ensure that the --authorization-mode argument is not set to AlwaysAllow (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 1.2.8Verify that RBAC is enabled (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 1.2.9Ensure that the APIPriorityAndFairness feature gate is enabled (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 1.3.1Ensure that controller manager healthz endpoints are protected by RBAC (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 1.3.2Ensure that the --use-service-account-credentials argument is set to true (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 1.3.3Ensure that the --service-account-private-key-file argument is set as appropriate (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 1.3.4Ensure that the --root-ca-file argument is set as appropriate (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 1.3.5Ensure that the --bind-address argument is set to 127.0.0.1 (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 1.4.1Ensure that the healthz endpoints for the scheduler are protected by RBAC (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 1.4.2Verify that the scheduler API service is protected by RBAC (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 2.1Ensure that the --cert-file and --key-file arguments are set as appropriate (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 2.2Ensure that the --client-cert-auth argument is set to true (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 2.3Ensure that the --auto-tls argument is not set to true (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 2.4Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriate (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 2.5Ensure that the --peer-client-cert-auth argument is set to true (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 2.6Ensure that the --peer-auto-tls argument is not set to true (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 2.7Ensure that a unique Certificate Authority is used for etcd (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 3.1.1Client certificate authentication should not be used for users (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 3.2.1Ensure that a minimal audit policy is created (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 3.2.2Ensure that the audit policy covers key security concerns (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.1.1Ensure that the kubelet service file permissions are set to 644 or more restrictive (Automated)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.1.10Ensure that the kubelet configuration file ownership is set to root:root (Automated)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.1.2Ensure that the kubelet service file ownership is set to root:root (Automated)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.1.3If proxy kube proxy configuration file exists ensure permissions are set to 644 or more restrictive (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.1.4If proxy kubeconfig file exists ensure ownership is set to root:root (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.1.5Ensure that the --kubeconfig kubelet.conf file permissions are set to 644 or more restrictive (Automated)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.1.6Ensure that the --kubeconfig kubelet.conf file ownership is set to root:root (Automated)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.1.7Ensure that the certificate authorities file permissions are set to 644 or more restrictive (Automated)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.1.8Ensure that the client certificate authorities file ownership is set to root:root (Automated)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.1.9Ensure that the kubelet --config configuration file has permissions set to 600 or more restrictive (Automated)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.2.1Activate Garbage collection in OpenShift Container Platform 4, as appropriate (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.2.10Ensure that the --rotate-certificates argument is not set to false (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.2.11Verify that the RotateKubeletServerCertificate argument is set to true (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.2.12Ensure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.2.2Ensure that the --anonymous-auth argument is set to false (Automated)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.2.3Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.2.4Ensure that the --client-ca-file argument is set as appropriate (Automated)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.2.5Verify that the read only port is not used or is set to 0 (Automated)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.2.6Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.2.7Ensure that the --make-iptables-util-chains argument is set to true (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.2.8Ensure that the kubeAPIQPS [--event-qps] argument is set to 0 or a level which ensures appropriate event capture (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 4.2.9Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 5.1.1Ensure that the cluster-admin role is only used where required (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 5.1.2Minimize access to secrets (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 5.1.3Minimize wildcard use in Roles and ClusterRoles (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 5.1.4Minimize access to create pods (Manual)Votes: 0GitHub stars: 2,182
- Cis Ocp V160 5.1.5Ensure that default service accounts are not actively used. (Manual)Votes: 0GitHub stars: 2,182