aws / aws/containers-roadmap

[service] [request]: compatibility matrix for EKS clusters against CIS benchmark recommendations.

Open
#2,629 0 comments 0 reactions 0 assignees View on GitHub
EKS Proposed
Dominant language
Shell
Stars
5.4k
Forks
334
PR merge metrics
No merged PRs in 30d

Description

### Community Note

* Please vote on this issue by adding a 👍 [reaction](https://blog.github.com/2016-03-10-add-reactions-to-pull-requests-issues-and-comments/) to the original issue to help the community and maintainers prioritize this request
* Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
* If you are interested in working on this issue or have submitted a pull request, please leave a comment

**Tell us about your request**
Currently we are using eks1.2.0 CIS benchmark and running kube-bench across our EKS clusters. we are currently on EKS 1.31 and I see a latest eks 1.5.0 benchmark available which is still an older version when checked in CIS site and the latest one available is CIS benchmark 1.7.0

**Which service(s) is this request for?**
This could be EKS with MNG

**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
I have searched for a compatibility matrix for EKS clusters against CIS benchmark recommendations but have not found any references.
There is no compatibility matrix available for CIS against EKS clusters.

**Are you currently working around this issue?**
we are currently using eks1.2.0 CIS benchmark and running kube-bench across our EKS clusters.

**Additional context**
Nothing at the moment. If the compatibility matrix can be published then it would be easier for customers to make sure they can use the right CIS benchmark version and keep the EKS clusters secure and complaint.

**Attachments**
If you think you might have additional information that you'd like to include via an attachment, please do - we'll take a look. (Remember to remove any personally-identifiable information.)

Contributor guide

Open the contributing guide

Research direction

No repository files, tests, or entry points are identified. Start by reviewing the cited EKS 1.31, CIS benchmark 1.2.0, 1.5.0, and 1.7.0 versions alongside the kube-bench context; done means publishing a compatibility matrix for EKS with managed node groups.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, kubernetes
Domain
cloud, documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.