Launched this week
k8s-audit

k8s-audit

30-second Kubernetes security check, kubectl and jq only

2 followers

One bash script, 16 read-only security checks, about 30 seconds. Privileged containers, missing NetworkPolicies, wildcard RBAC, hostPath mounts, :latest tags, service account tokens mounted where they should not be. Needs only kubectl and jq. Nothing is deployed into your cluster and nothing leaves your machine. It is the fast first pass before kube-bench or Kubescape, not a replacement. MIT licensed, and it now writes a single-file HTML report you can share.

k8s-audit makers

Here are the founders, developers, designers and product people who worked on k8s-audit