{"repo":"aws-samples/hardeneks","free":true,"listed":false,"github":"https://github.com/aws-samples/hardeneks","clone":"git clone https://github.com/aws-samples/hardeneks.git","description":"Runs checks to see if an EKS cluster follows EKS Best Practices.","language":"Python","stars":959,"topics":["aws","best-practices","eks","k8s"],"license":"MIT-0","category":"deployment-docker-iac","readme_excerpt":"Hardeneks Runs checks to see if an EKS cluster follows EKS Best Practices. Quick Start : Usage : Options : --region TEXT : AWS region of the cluster. Ex: us-east-1 --context TEXT : K8s context --cluster TEXT : EKS Cluster name --namespace TEXT : Namespace to be checked (default is all namespaces) --config TEXT : Path to a hardeneks config file --export-txt TEXT : Export the report in txt format --export-csv TEXT : Export the report in csv format --export-html TEXT : Export the report in html format --export-json TEXT : Export the report in json format --export-security-hub : Export failed checks to AWS Security Hub --insecure-skip-tls-verify : Skip TLS verification --width : Width of the output (defaults to terminal size) --height : Height of the output (defaults to terminal size) --help : Show this message and exit. - K8S CONTEXT You can get the contexts by running: or get the current context by running: - CLUSTER NAME You can get the cluster names by running: Configuration File : Default behavior is to run all the checks. If you want to provide your own config file to specify list of rules to run, you can use the --config flag.You can also add namespaces to be skipped. Following is a sample config file: Permissions In order to run hardeneks we need to have some permissions both on AWS side and k8s side. Minimal IAM role policy for all checks Minimal ClusterRole for all checks For Developers Prerequisites : This cli uses poetry. Follow instructions that are outlined here to ","default_branch":null,"files":null,"tree":[],"storefront":"/r/aws-samples","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/aws-samples/hardeneks/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}