Skip to content

feat: add CIS GKE 1.9.0 configuration files and controls#2002

Open
jesayafn wants to merge 16 commits intoaquasecurity:mainfrom
jesayafn:dev/cis-gke-1.9.0
Open

feat: add CIS GKE 1.9.0 configuration files and controls#2002
jesayafn wants to merge 16 commits intoaquasecurity:mainfrom
jesayafn:dev/cis-gke-1.9.0

Conversation

@jesayafn
Copy link
Copy Markdown

@jesayafn jesayafn commented Dec 3, 2025

feat: add CIS GKE 1.9.0 configuration files and controls

Changelog

  • Added CIS Google Kubernetes Engine Benchmark v1.8.0

@jesayafn jesayafn marked this pull request as ready for review December 18, 2025 05:22
@afdesk
Copy link
Copy Markdown
Collaborator

afdesk commented Feb 11, 2026

@jesayafn thanks for your contribution!
could you pls fix the yaml linter errors?

@jesayafn
Copy link
Copy Markdown
Author

Hi @afdesk

I've added the trailing space fix

Comment thread cfg/gke-1.9.0/managedservices.yaml Outdated
Comment thread cfg/gke-1.9.0/managedservices.yaml Outdated
Comment thread cfg/gke-1.9.0/managedservices.yaml Outdated
Comment thread cfg/gke-1.9.0/managedservices.yaml
--flatten="bindings[].members" \
--format='table(bindings.members,bindings.role)' \
--filter="bindings.role:roles/storage.admin OR bindings.role:roles/storage.objectAdmin OR bindings.role:roles/storage.objectCreator OR bindings.role:roles/storage.legacyBucketOwner OR bindings.role:roles/storage.legacyBucketWriter OR bindings.role:roles/storage.legacyObjectOwner"
type: "manual"
Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ditto

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Keep it manual as long as the source states it's manual

Comment thread cfg/gke-1.9.0/managedservices.yaml Outdated
Comment thread cfg/gke-1.9.0/managedservices.yaml
Comment thread cfg/gke-1.9.0/managedservices.yaml Outdated
@afdesk
Copy link
Copy Markdown
Collaborator

afdesk commented Feb 20, 2026

@jesayafn thanks a lot for your efforts!
I left some comments here, but it looks great!

@LaibaBareera WDYT?

@jesayafn
Copy link
Copy Markdown
Author

Hi @afdesk. I added commits, kindly review

@afdesk
Copy link
Copy Markdown
Collaborator

afdesk commented Feb 27, 2026

@jesayafn thanks for your efforts!
could you rebase the branch with main?

jesayafn and others added 9 commits February 27, 2026 15:07
…anaged services section to follow current document
…olicies section to follow current document, and update version field in all related config file
…ude automated audit and remediation steps

Need Google CLI in the same host or pod with proper permission on the service account or user account to run `serviceusage.services.list`.

Co-authored-by: GitHub Copilot <noreply@github.com>
…heck and remove redundant remediation section
…th automated audit and scoring

Needed permission for audit command:
- `container.nodePools.get` in case the NODE_POOL variable is not set
- `container.clusters.get`

Co-authored-by: GitHub Copilot <noreply@github.com>
@jesayafn
Copy link
Copy Markdown
Author

@jesayafn thanks for your efforts! could you rebase the branch with main?

done @afdesk

@LaibaBareera
Copy link
Copy Markdown
Collaborator

@jesayafn Thanks for your efforts.
@afdesk LGTM too.

@afdesk
Copy link
Copy Markdown
Collaborator

afdesk commented Mar 10, 2026

@jesayafn there are some linter errors...
could you pls fix it?
thanks a lot!

@afdesk
Copy link
Copy Markdown
Collaborator

afdesk commented Mar 10, 2026

@jesayafn
Copy link
Copy Markdown
Author

I added a fix following the linter error feedback.

Kindly check @afdesk

@LaibaBareera
Copy link
Copy Markdown
Collaborator

@jesayafn can you rebase this branch with main

@LaibaBareera
Copy link
Copy Markdown
Collaborator

@jesayafn ,
Can you please update the getPlatformBenchmarkVersion function in the cmd/utils.go file to include GKE-1.9 for Kubernetes versions v1.31, v1.32, v1.33, and v1.34?

@jesayafn
Copy link
Copy Markdown
Author

@LaibaBareera Kindly check my recent changes and rebase

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants