Gke Workload Security

作者 google55b4e13eba6d无许可证21K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Audits, configures, and hardens workload-level security controls for Google Kubernetes Engine (GKE) applications and namespaces. Covers running security audits (`audit_cluster.sh`), enforcing Network Policies (default-deny and Dataplane V2 logging), isolating high-risk pods inside GKE Sandbox (`gVisor`), enforcing Pod Security Standards (`restricted` labeling) and pod securityContext, and mounting Secret Manager secrets via CSI (`SecretProviderClass`). Use when auditing workload security posture, isolating namespaces, applying pod security standards, or configuring network policies and secret volume mounts. Don't use for Workload Identity (use gke-workload-identity), cluster-wide control plane security, RBAC hardening, Binary Authorization, Shielded Nodes, or enabling platform-level GKE add-ons (use gke-platform-security instead).

精选包含脚本SecurityDevOps & Cloud

仅公开文件列表。将技能安装到工作区后即可查看文件内容。

路径大小类型
assets/default-deny-netpol.yaml235 Bapplication/yaml
assets/workload-identity-pod.yaml1.2 KBapplication/yaml
scripts/audit_cluster.sh2.2 KBtext/plain
SKILL.md7.6 KBtext/markdown

来源与署名

来源:google/skills位于skills/cloud/gke-workload-security提交55b4e13

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架

更多来自 google/skills 的技能