Security Summary

Falco

Falcoarrow-up-right, an open-source cloud-native runtime security project, is the de facto Kubernetes threat detection engine.

Other tools you might have to be familiar with are sysdigarrow-up-right or traceearrow-up-right

For all available fields, we can check https://falco.org/docs/rules/supported-fieldsarrow-up-right

CIS Benchmark

Tools:

  • kube-bench

  • (docker bench)

Open Policy Agent and Gatekeeper

restrict images

kube-mgmt

gVisor

trivy

Static Analysis CI/CD

  • Pod Security Policy / OPA

Last updated