{"id":13451405,"url":"https://github.com/ksoclabs/awesome-kubernetes-security","last_synced_at":"2026-01-31T13:26:43.193Z","repository":{"id":37534302,"uuid":"187921415","full_name":"ksoclabs/awesome-kubernetes-security","owner":"ksoclabs","description":"A curated list of awesome Kubernetes security resources","archived":false,"fork":false,"pushed_at":"2023-12-15T05:19:31.000Z","size":44,"stargazers_count":951,"open_issues_count":4,"forks_count":127,"subscribers_count":31,"default_branch":"master","last_synced_at":"2026-01-25T00:52:29.675Z","etag":null,"topics":["awesome-list","kubernetes","kubernetes-security"],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ksoclabs.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null}},"created_at":"2019-05-21T22:18:25.000Z","updated_at":"2026-01-21T20:47:14.000Z","dependencies_parsed_at":"2024-01-05T23:56:50.000Z","dependency_job_id":null,"html_url":"https://github.com/ksoclabs/awesome-kubernetes-security","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/ksoclabs/awesome-kubernetes-security","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ksoclabs%2Fawesome-kubernetes-security","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ksoclabs%2Fawesome-kubernetes-security/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ksoclabs%2Fawesome-kubernetes-security/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ksoclabs%2Fawesome-kubernetes-security/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ksoclabs","download_url":"https://codeload.github.com/ksoclabs/awesome-kubernetes-security/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ksoclabs%2Fawesome-kubernetes-security/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28944490,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-31T13:02:32.153Z","status":"ssl_error","status_checked_at":"2026-01-31T13:00:07.528Z","response_time":128,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["awesome-list","kubernetes","kubernetes-security"],"created_at":"2024-07-31T07:00:53.385Z","updated_at":"2026-01-31T13:26:43.162Z","avatar_url":"https://github.com/ksoclabs.png","language":null,"funding_links":[],"categories":["Kubernetes","Others","Инструменты","Other Lists","Web","kubernetes","Community","Tools"],"sub_categories":["Безопасность Kubernetes","TeX Lists","Other Awesome Lists","Kubernetes"],"readme":"# :lock: awesome-kubernetes-security [![Awesome](https://awesome.re/badge.svg)](https://awesome.re)\n\nA curated list of awesome Kubernetes security resources. Can you dig it?\n\n## Open Source Projects\n\n- [aad-pod-identity](https://github.com/Azure/aad-pod-identity/) -  Assign Azure AD idenitites to pods in Kubernetes, in order to access Azure resources\n- [audit2rbac](https://github.com/liggitt/audit2rbac) - Autogenerate RBAC policies based on Kubernetes audit logs\n- [CDK](https://github.com/cdk-team/CDK) - Zero Dependency Container Penetration Toolkit\n- [Deepfence ThreatMapper](https://github.com/deepfence/ThreatMapper) - Apache v2, powerful runtime vulnerability scanner for kubernetes, virtual machines and serverless\n- [cnspec](https://cnspec.io) - Scan Kubernetes clusters, containers, and manifest files for vulnerabilities and misconfigurations\n- [falco](https://github.com/falcosecurity/falco) - Container Native Runtime Security\n- [KBOM](https://github.com/ksoclabs/kbom) - Kubernetes Bill of Materials Toolkit\n- [kdigger](https://github.com/quarkslab/kdigger) - Kubernetes focused container assessment and context discovery tool for penetration testing\n- [kiam](https://github.com/uswitch/kiam) - Integrate AWS IAM with Kubernetes\n- [kube-bench](https://github.com/aquasecurity/kube-bench) - Check whether Kubernetes is deployed according to security best practics\n- [kube-hunter](https://github.com/aquasecurity/kube-hunter) - Hunt for security weaknesses in Kubernetes clusters\n- [kube-psp-advisor](https://github.com/sysdiglabs/kube-psp-advisor) - Help building an adaptive and fine-grained pod security policy\n- [kube-scan](https://github.com/octarinesec/kube-scan) - k8s cluster risk assessment tool\n- [kubescape](https://github.com/kubescape/kubescape) - k8s risk analysis, security compliance, and misconfiguration scanning.\n- [kubelight - WIP but promising](https://github.com/OWASP/KubeLight) - OWASP project to scan your Kubernetes Cluster for Security \u0026 Compliance.\n- [Kubei](https://github.com/Portshift/kubei) - Vulnerabilities scanner for Kubernetes clusters\n- [kube2iam](https://github.com/jtblin/kube2iam) - Provide different AWS IAM roles for pods running on Kubernetes\n- [kubeaudit](https://github.com/Shopify/kubeaudit) - Audit your Kubernetes clusters against common security controls\n- [kubectl-bindrole](https://github.com/Ladicle/kubectl-bindrole) - Find Kubernetes roles bound to a specified ServiceAccount, Group or User\n- [kubectl-dig](https://github.com/sysdiglabs/kubectl-dig) - Deep Kubernetes visibility from the kubectl\n- [kubectl-kubesec](https://github.com/stefanprodan/kubectl-kubesec) - Scan Kubernetes pods, deployments, daemonsets and statefulsets with kubesec.io\n- [kubectl-who-can](https://github.com/aquasecurity/kubectl-who-can) - Show who has permissions to \\\u003cverb\\\u003e \\\u003cresource\\\u003e in Kubernetes\n- [OWASP Top Ten for Kubernetes](https://owasp.org/www-project-kubernetes-top-ten/) -  The Top Ten is a prioritized list of these risks backed by data collected from organizations varying in maturity and complexity\n- [terrascan](https://github.com/accurics/terrascan) - Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure\n- [kyverno](https://github.com/nirmata/kyverno) - Kubernetes Native Policy Management\n- [netchecks](https://github.com/hardbyte/netchecks/) - Tool to validate assumptions about the network\n- [rakkess](https://github.com/corneliusweig/rakkess) - Review access matrix for Kubernetes server resources\n- [rback](https://github.com/team-soteria/rback) - RBAC in Kubernetes visualizer\n- [red-kube](https://github.com/lightspin-tech/red-kube) - K8S Adversary Emulation Based on kubectl\n- [steampipe](https://github.com/turbot/steampipe) - Use SQL to query your cloud services (AWS, Azure, GCP and more) running Kubernetes\n- [steampipe-kubernetes](https://github.com/turbot/steampipe-plugin-kubernetes) - Use SQL to query your Kubernetes resources\n- [steampipe-kubernetes-compliance](https://github.com/turbot/steampipe-mod-kubernetes-compliance) - Kubernetes compliance scanning tool for CIS, NSA \u0026 CISA Cybersecurity technical report for Kubernetes hardening.\n- [trivy](https://github.com/aquasecurity/trivy) - A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable for CI\n- [trivy-operator](https://github.com/aquasecurity/trivy-operator) - Kubernetes-native security (Vulnerabilities,IaC MisConfig,Exposed Secrets,RBAC Assessment,Compliance and more) toolkit for kubernetes\n- [kubernetes-rbac-audit](https://github.com/cyberark/kubernetes-rbac-audit) - Tool for auditing RBACs in Kubernetes\n- [kubernetes-external-secrets](https://github.com/external-secrets/kubernetes-external-secrets) - Tool to get External Secrets from Hashicorp Vault and AWS SSM\n- [vault-secrets-operator](https://github.com/ricoberger/vault-secrets-operator) - An operator to create Kubernetes secrets from Vault for a secure GitOps based workflow\n\n## General Resources\n\n- [Kubernetes Security and Disclosure Information](https://kubernetes.io/docs/reference/issues-security/security/)\n- [Kubernetes Security](https://kubernetes-security.info/)\n- [GKE Security Bulletins](https://cloud.google.com/kubernetes-engine/docs/security-bulletins)\n- [CKS Certified Kubernetes Security Specialist resources repo](https://github.com/walidshaari/Certified-Kubernetes-Security-Specialist)\n- [Kubernetes Security Checklist and Requirements](https://github.com/Vinum-Security/kubernetes-security-checklist)\n- [OWASP Kubernetes Security Cheatsheet](https://cheatsheetseries.owasp.org/cheatsheets/Kubernetes_Security_Cheat_Sheet.html)\n- [Securing Kubernetes Clusters](https://www.cyberark.com/resources/threat-research-blog/securing-kubernetes-clusters-by-eliminating-risky-permissions)\n- [Kubernetes Security : 6 Best Practices for 4C Security Model](https://spacelift.io/blog/kubernetes-security)\n\n## Twitter Accounts\n\n- [Andrew Martin](https://twitter.com/sublimino)\n- [Ann N Wallace](https://twitter.com/annnwallace)\n- [Annabelle Bertucio](https://twitter.com/WhyHiAnnabelle)\n- [Brad Geessaman](https://twitter.com/bradgeesaman)\n- [Duffie Cooley](https://twitter.com/mauilion)\n- [Erik St. Martin](https://twitter.com/erikstmartin)\n- [Greg Castle](https://twitter.com/mrgcastle)\n- [Ian Coldwater](https://twitter.com/iancoldwater)\n- [Jimmy Mesta](https://twitter.com/jimmesta)\n- [Jordan Liggitt](https://twitter.com/liggitt)\n- [learnk8s](https://twitter.com/learnk8s)\n- [Liz Rice](https://twitter.com/lizrice)\n- [Mark Manning](https://twitter.com/antitree)\n- [Maya Kaczorowski](https://twitter.com/MayaKaczorowski)\n- [Michael Ducy](https://twitter.com/mfdii)\n- [Michael Hausenblas](https://twitter.com/mhausenblas)\n- [Peter Benjamin](https://twitter.com/petermbenjamin)\n- [Rory McCune](https://twitter.com/raesene)\n- [Tabitha Sable](https://twitter.com/TabbySable)\n- [Tim Allclair](https://twitter.com/tallclair)\n- [Timothy St. Clair](https://twitter.com/timothysc)\n- [Sangam Biradar](https://github.com/sangam14)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fksoclabs%2Fawesome-kubernetes-security","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fksoclabs%2Fawesome-kubernetes-security","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fksoclabs%2Fawesome-kubernetes-security/lists"}