Document and contextualise kube-bench results for KKP
Nobody has claimed this yet.
- Dominant language
- SCSS
- Stars
- 19
- Forks
- 117
- Avg merge
- 13h 29m
- Merged PRs (30d)
- 13
Description
We should look into publishing results for https://github.com/aquasecurity/kube-bench on a stock KKP user cluster to our docs. Some tests might also be false-negatives, so we need to document why we believe those are not valid, so users running kube-bench on their own can understand the results they are getting.
I think it would be best to store the results in some data format (e.g. JSON, maybe kube-bench supports that as output), enrich it with context and render it into a document nicely. That way, we might be able to update it nicely.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by running kube-bench against a stock KKP user cluster and inspect whether it supports JSON output. Identify the checks that produce false negatives, record the relevant context alongside the results, and render the collected data in the KKP documentation. Done means users can understand both the published results and why any reported failures are not valid.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- kubernetes
- Domain
- documentation, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100