{"repo":"krol3/container-security-checklist","free":true,"listed":false,"github":"https://github.com/krol3/container-security-checklist","clone":"git clone https://github.com/krol3/container-security-checklist.git","description":"Checklist for container security - devsecops practices","language":null,"stars":1619,"topics":["containers","devsecops","security"],"license":"Apache-2.0","category":"security-tools","readme_excerpt":"Container Security Checklist: From the image to the workload Table Of Contents - Cloud Native challenges - Container Threat Model - Container Security Checklist - Supply Chain Security - Secure the Build - Secure Supply Chain - Hardening Code - Secure SDLC (Software Development Life Cycle) - Secure the Image - Hardening - Image Scanning - Image Signing - Secure the Container Registry - Registry Resources - Secure the Container Runtime - Why is important Runtime Security? - Constraints - Docker Security - Secure the Infrastructure - Secure the Data - Secrets Management Tools - Secure the Workloads... Running the containers - Common Containers Attacks - Container Security Guides - Further reading - Collaborate --- Cloud Native challenges Legacy apps Cloud Native apps Cloud Native Security ---------- :-------------: ------: Discrete, infrequent releases frequent releases, using CI/CD Shifting left with automated testing Very little open source Open source everywhere SCA - Software composition analysis Proprietary software Proprietary code, Open source, Third-party software Software supply chain risk Persistent workloads Ephemeral workloads. Ensure that your containers are stateless and immutable Runtime controls that follow the workload Hypervisor or hardware isolation Shared kernel, obscured OS Enforce least privilege on each workload Permanent address Orchestrated containers. Kubernetes creates DNS records for services and pods Identity-based segmentation Vertical control of t","default_branch":null,"files":null,"tree":[],"storefront":"/r/krol3","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/krol3/container-security-checklist/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}