From 9643b0c11bdafd26ea0ac5127325aa8cb09f0c03 Mon Sep 17 00:00:00 2001 From: mrichomme Date: Sat, 14 Nov 2020 22:36:57 +0100 Subject: Refactor Integration official documentation Issue-ID: INT-1736 Signed-off-by: mrichomme Change-Id: Ia7b6425358eb9b07e293881dabd5345697af1c39 --- docs/files/csv/tests-security.csv | 9 +++++++++ 1 file changed, 9 insertions(+) create mode 100644 docs/files/csv/tests-security.csv (limited to 'docs/files/csv/tests-security.csv') diff --git a/docs/files/csv/tests-security.csv b/docs/files/csv/tests-security.csv new file mode 100644 index 000000000..07e05d0ba --- /dev/null +++ b/docs/files/csv/tests-security.csv @@ -0,0 +1,9 @@ +Tests;Description;Code;Comments +root_pods;check that pods are nor using root user or started as root; `bash script `__; kubectl +unlimitted_pods;check that limits are set for pods;`bash script `__; kubectl +cis_kubernetes;perform the k8s cis test suite (upstream src aquasecurity);`bash script `__;`kube-bench `__ +nonssl_endpoints;check that all public HTTP endpoints exposed in ONAP cluster use SSL tunnels;`Go script `__;kubetl, nmap +http_public_endpoints;check that there is no public http endpoints exposed in ONAP cluster;`bash script `__;kubectl,nmap +jdpw_ports;check that there are no internal java ports;`bash script `__;kubectl, procfs +kube_hunter;security suite to search k8s vulnerabilities (upstream src aquasecurity);`kube-Hunter `__; `kube-Hunter `__ +versions;check that Java and Python are available only in versions recommended by SECCOM. This test is long and run only in Weekly CI chains;`python module `__;cerberus, kubernetes python lib, -- cgit 1.2.3-korg