{"repo":"appvia/krane","free":true,"listed":false,"github":"https://github.com/appvia/krane","clone":"git clone https://github.com/appvia/krane.git","description":"Kubernetes RBAC static analysis & visualisation tool","language":"Ruby","stars":744,"topics":["kubernetes","rbac","analysis","visualisation","redisgraph","static-analysis","rbac-configuration","rbac-roles","rbac-management","k8s"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"Krane Kubernetes RBAC Analysis made Easy Krane is a simple Kubernetes RBAC static analysis tool. It identifies potential security risks in K8s RBAC design and makes suggestions on how to mitigate them. Krane dashboard presents current RBAC security posture and lets you navigate through its definition. Features - RBAC Risk rules - Krane evaluates a set of built-in RBAC risk rules. These can be modified or extended with a set of custom rules. - Portability - Krane can run in one of the following modes: Locally as a CLI or docker container. In CI/CD pipelines as a step action detecting potential RBAC flaws before it gets applied to the cluster. As a standalone service continuously analysing state of RBAC within a Kubernetes cluster. - Reporting - Krane produces an easy to understand RBAC risk report in machine-readable format. - Dashboard - Krane comes with a simple Dashboard UI helping you understand in-cluster RBAC design. Dashboard presents high-level overview of RBAC security posture and highlights detected risks. It also allows for further RBAC controls inspection via faceted tree and graph network views. - Alerting - It will alert on detected medium and high severity risks via its Slack integration. - RBAC in the Graph - Krane indexes entirety of Kubernetes RBAC in a local Graph database which makes any further ad-hoc interrogating of RBAC data easy, with arbitrary CypherQL queries. Contents - Quick Start - Usage Guide - Architecture - Kubernetes Deployment - Notifications","default_branch":null,"files":null,"tree":[],"storefront":"/r/appvia","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/appvia/krane/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}