Launched this week

k8s-audit
30-second Kubernetes security check, kubectl and jq only
2 followers
30-second Kubernetes security check, kubectl and jq only
2 followers
One bash script, 16 read-only security checks, about 30 seconds. Privileged containers, missing NetworkPolicies, wildcard RBAC, hostPath mounts, :latest tags, service account tokens mounted where they should not be. Needs only kubectl and jq. Nothing is deployed into your cluster and nothing leaves your machine. It is the fast first pass before kube-bench or Kubescape, not a replacement. MIT licensed, and it now writes a single-file HTML report you can share.
k8s-audit Reviews
Pros
Cons
Reviews