[service] [request]: compatibility matrix for EKS clusters against CIS benchmark recommendations.
- Dominant language
- Shell
- Stars
- 5.4k
- Forks
- 334
- PR merge metrics
- No merged PRs in 30d
Description
### Community Note
* Please vote on this issue by adding a 👍 [reaction](https://blog.github.com/2016-03-10-add-reactions-to-pull-requests-issues-and-comments/) to the original issue to help the community and maintainers prioritize this request
* Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
* If you are interested in working on this issue or have submitted a pull request, please leave a comment
**Tell us about your request**
Currently we are using eks1.2.0 CIS benchmark and running kube-bench across our EKS clusters. we are currently on EKS 1.31 and I see a latest eks 1.5.0 benchmark available which is still an older version when checked in CIS site and the latest one available is CIS benchmark 1.7.0
**Which service(s) is this request for?**
This could be EKS with MNG
**Tell us about the problem you're trying to solve. What are you trying to do, and why is it hard?**
I have searched for a compatibility matrix for EKS clusters against CIS benchmark recommendations but have not found any references.
There is no compatibility matrix available for CIS against EKS clusters.
**Are you currently working around this issue?**
we are currently using eks1.2.0 CIS benchmark and running kube-bench across our EKS clusters.
**Additional context**
Nothing at the moment. If the compatibility matrix can be published then it would be easier for customers to make sure they can use the right CIS benchmark version and keep the EKS clusters secure and complaint.
**Attachments**
If you think you might have additional information that you'd like to include via an attachment, please do - we'll take a look. (Remember to remove any personally-identifiable information.)
Contributor guide
Research direction
No repository files, tests, or entry points are identified. Start by reviewing the cited EKS 1.31, CIS benchmark 1.2.0, 1.5.0, and 1.7.0 versions alongside the kube-bench context; done means publishing a compatibility matrix for EKS with managed node groups.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, kubernetes
- Domain
- cloud, documentation, security
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100