All authors

Claude Skills by CyberStrikeus
github.com/CyberStrikeus7,689 skills0 installs16,544 views
- Cis Gke Autopilot V130 5.4.2Ensure Control Plane Authorized Networks is Enabled (Manual)Votes: 0GitHub stars: 2,182
- Cis Gke Autopilot V130 5.4.3Ensure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke Autopilot V130 5.4.4Ensure clusters are created with Private Nodes (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke Autopilot V130 5.4.5Ensure use of Google-managed SSL Certificates (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke Autopilot V130 5.5.1Manage Kubernetes RBAC users with Google Groups for GKE (Manual)Votes: 0GitHub stars: 2,182
- Cis Gke Autopilot V130 5.6.1Enable Customer-Managed Encryption Keys (CMEK) for GKE Persistent Disks (PD) (Manual)Votes: 0GitHub stars: 2,182
- Cis Gke Autopilot V130 5.7.1Enable Security Posture (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 3.1.1Ensure that the proxy kubeconfig file permissions are set to 644 or more restrictive (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 3.1.2Ensure that the proxy kubeconfig file ownership is set to root:root (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 3.1.3Ensure that the kubelet configuration file has permissions set to 644 (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 3.1.4Ensure that the kubelet configuration file ownership is set to root:root (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 3.2.1Ensure that the Anonymous Auth is Not Enabled Draft (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 3.2.2Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 3.2.3Ensure that a Client CA File is Configured (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 3.2.4Ensure that the --read-only-port is disabled (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 3.2.5Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 3.2.6Ensure that the --make-iptables-util-chains argument is set to true (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 3.2.7Ensure that the --eventRecordQPS argument is set to 0 or a level which ensures appropriate event capture (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 3.2.8Ensure that the --rotate-certificates argument is not present or is set to true (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 3.2.9Ensure that the RotateKubeletServerCertificate argument is set to true (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.1.1Ensure that the cluster-admin role is only used where required (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.1.10Avoid non-default bindings to system:authenticated (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.1.2Minimize access to secrets (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.1.3Minimize wildcard use in Roles and ClusterRoles (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.1.4Ensure that default service accounts are not actively used (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.1.5Ensure that Service Account Tokens are only mounted where necessary (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.1.6Avoid use of system:masters group (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.1.7Limit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster (Manual)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.1.8Avoid bindings to system:anonymous (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.1.9Avoid non-default bindings to system:unauthenticated (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.2.1Ensure that the cluster enforces Pod Security Standard Baseline profile or stricter for all namespaces (Manual)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.3.1Ensure that the CNI in use supports Network Policies (Manual)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.3.2Ensure that all Namespaces have Network Policies defined (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.4.1Prefer using secrets as files over secrets as environment variables (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.4.2Consider external secret storage (Manual)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.5.1Configure Image Provenance using ImagePolicyWebhook admission controller (Manual)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.6.1Create administrative boundaries between resources using namespaces (Manual)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.6.2Ensure that the seccomp profile is set to RuntimeDefault in the pod definitions (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.6.3Apply Security Context to Pods and Containers (Manual)Votes: 0GitHub stars: 2,182
- Cis Gke V170 4.6.4The default namespace should not be used (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 5.1.1Ensure Image Vulnerability Scanning is enabled (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 5.1.2Minimize user access to Container Image repositories (Manual)Votes: 0GitHub stars: 2,182
- Cis Gke V170 5.1.3Minimize cluster access to read-only for Container Image repositories (Manual)Votes: 0GitHub stars: 2,182
- Cis Gke V170 5.1.4Ensure only trusted container images are used (Manual)Votes: 0GitHub stars: 2,182
- Cis Gke V170 5.10.1Ensure Kubernetes Web UI is Disabled (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 5.10.2Ensure that Alpha clusters are not used for production workloads (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 5.10.3Consider GKE Sandbox for running untrusted workloads (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 5.10.4Ensure use of Binary Authorization (Automated)Votes: 0GitHub stars: 2,182
- Cis Gke V170 5.10.5Enable Security Posture (Manual)Votes: 0GitHub stars: 2,182
- Cis Gke V170 5.2.1Ensure GKE clusters are not running using the Compute Engine default service account (Automated)Votes: 0GitHub stars: 2,182