All authors
CyberStrikeus avatar

Claude Skills by CyberStrikeus

github.com/CyberStrikeus
1,315 skillsA× 1,256B× 57D× 20 installs318 views
Cis Ocp V190 1.1.21A

Ensure that the OpenShift PKI key file permissions are set to 600 (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.3A

Ensure that the controller manager pod specification file permissions are set to 600 or more restrictive (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.4A

Ensure that the controller manager pod specification file ownership is set to root:root (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.5A

Ensure that the scheduler pod specification file permissions are set to 600 or more restrictive (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.6A

Ensure that the scheduler pod specification file ownership is set to root:root (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.7A

Ensure that the etcd pod specification file permissions are set to 600 or more restrictive (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.8A

Ensure that the etcd pod specification file ownership is set to root:root (Manual)

securitygobash
0
291
Cis Ocp V190 1.1.9A

Ensure that the Container Network Interface file permissions are set to 600 or more restrictive (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.1A

Ensure that anonymous requests are authorized (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.10A

Ensure that the admission control plugin ServiceAccount is set (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.11A

Ensure that the admission control plugin NamespaceLifecycle is set (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.12A

Ensure that the admission control plugin SecurityContextConstraint is set (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.13A

Ensure that the admission control plugin NodeRestriction is set (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.14A

Ensure that the --insecure-bind-address argument is not set (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.15A

Ensure that the --insecure-port argument is set to 0 (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.16A

Ensure that the --secure-port argument is not set to 0 (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.17B

Ensure that the healthz endpoint is protected by RBAC (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.18A

Ensure that the --audit-log-path argument is set (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.19A

Ensure that the audit logs are forwarded off the cluster for retention (Manual)

securitygokubernetes
0
291
Cis Ocp V190 1.2.2A

Use https for kubelet connections (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.20A

Ensure that the maximumRetainedFiles argument is set to 10 or as appropriate (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.21A

Configure Kubernetes API Server Maximum Audit Log Size (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.22A

Ensure that the --request-timeout argument is set (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.23A

Ensure that the --service-account-lookup argument is set to true (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.24A

Ensure that the --service-account-key-file argument is set as appropriate (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.25A

Ensure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.26A

Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.27A

Ensure that the --client-ca-file argument is set as appropriate (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.28A

Ensure that the --etcd-cafile argument is set as appropriate (Manual)

securityrustgo
0
291
Cis Ocp V190 1.2.29A

Ensure that encryption providers are appropriately configured (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.3A

Ensure that the kubelet uses certificates to authenticate (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.30A

Ensure that the API Server only makes use of Strong Cryptographic Ciphers (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.31A

Ensure unsupported configuration overrides are not used (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.4A

Verify that the kubelet certificate authority is set as appropriate (Manual)

securityrustgo
0
291
Cis Ocp V190 1.2.5A

Ensure that the --authorization-mode argument is not set to AlwaysAllow (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.6A

Verify that RBAC is enabled (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.7A

Ensure that the APIPriorityAndFairness feature gate is enabled (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.8A

Ensure that the admission control plugin AlwaysAdmit is not set (Manual)

securitygobash
0
291
Cis Ocp V190 1.2.9A

Ensure that the admission control plugin AlwaysPullImages is not set (Manual)

securityrustgo
0
291
Cis Ocp V190 1.3.1B

Ensure that controller manager healthz endpoints are protected by RBAC (Manual)

securitygobash
0
291
Cis Ocp V190 1.3.2A

Ensure that the --use-service-account-credentials argument is set to true (Manual)

securitygobash
0
291
Cis Ocp V190 1.3.3A

Ensure that the --service-account-private-key-file argument is set as appropriate (Manual)

securitygobash
0
291
Cis Ocp V190 1.3.4A

Ensure that the --root-ca-file argument is set as appropriate (Manual)

securityrustgo
0
291
Cis Ocp V190 1.4.1B

Ensure that the healthz endpoints for the scheduler are protected by RBAC (Manual)

securitygobash
0
291
Cis Ocp V190 1.4.2B

Verify that the scheduler API service is protected by RBAC (Manual)

securitygobash
0
291
Cis Ocp V190 2.1A

Ensure that the --cert-file and --key-file arguments are set as appropriate (Manual)

securitygobash
0
291
Cis Ocp V190 2.2A

Ensure that the --client-cert-auth argument is set to true (Manual)

securitygobash
0
291
Cis Ocp V190 2.3A

Ensure that the --auto-tls argument is not set to true (Manual)

securityrustgo
0
291
Cis Ocp V190 2.4A

Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriate (Manual)

securitygobash
0
291
Cis Ocp V190 2.5A

Ensure that the --peer-client-cert-auth argument is set to true (Manual)

securitygobash
0
291