Skip to content

feat(compliance): add support for eks-cis-1.8#557

Open
mattcarp12 wants to merge 34 commits intoaquasecurity:mainfrom
mattcarp12:feat/eks-cis-1.8
Open

feat(compliance): add support for eks-cis-1.8#557
mattcarp12 wants to merge 34 commits intoaquasecurity:mainfrom
mattcarp12:feat/eks-cis-1.8

Conversation

@mattcarp12
Copy link
Copy Markdown

This PR adds pkg/compliance/eks-cis-1.8.yaml which is consistent with the CIS Benchmark for EKS version 1.8.

Closes #10460.

Maps CIS 3.2.9 to KCV-0091 and CMD-0044 to verify RotateKubeletServerCertificate
is enabled on worker nodes.

Intentionally omitted KCV-0038 (which audits the kube-controller-manager)
because EKS is a managed service where the Control Plane is abstracted from
the user and cannot be audited or modified via node collection.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant