{"repo":"zegl/kube-score","free":true,"listed":false,"github":"https://github.com/zegl/kube-score","clone":"git clone https://github.com/zegl/kube-score.git","description":"Kubernetes object analysis with recommendations for improved reliability and security. kube-score actively prevents downtime and bugs in your Kubernetes YAML and Charts. Static code analysis for Kubernetes.","language":"Go","stars":3097,"topics":["kubernetes","linter","ci","go","helm","charts","static-code-analysis","kube-score","security","security-scanner"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"kube-score --- kube-score is a tool that performs static code analysis of your Kubernetes object definitions. The output is a list of recommendations of what you can improve to make your application more secure and resilient. You can test kube-score out in the browser with the online demo (source). Installation kube-score is easy to install, and is available from the following sources: Distribution Command / Link ----------------------------------------------------- ----------------------------------------------------------------------------------------- Pre-built binaries for macOS, Linux, and Windows GitHub releases Docker docker pull zegl/kube-score (Docker Hub) Homebrew (macOS and Linux) brew install kube-score Krew (macOS and Linux) kubectl krew install score Sponsors Your company here? Checks For a full list of checks, see README CHECKS.md. Container limits (should be set) Pod is targeted by a NetworkPolicy , both egress and ingress rules are recommended Deployments and StatefulSets should have a PodDisruptionPolicy Deployments and StatefulSets should have host PodAntiAffinity configured Container probes, a readiness should be configured, and should not be identical to the liveness probe. Read more in README PROBES.md. Container securityContext, run as high number user/group, do not run as root or with privileged root fs. Read more in README SECURITYCONTEXT.md. Stable APIs, use a stable API if available (supported: Deployments, StatefulSets, DaemonSet) Example output Us","default_branch":null,"files":null,"tree":[],"storefront":"/r/zegl","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/zegl/kube-score/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}