Skip to content

Commit ce2fce9

Browse files
authored
Merge pull request #5824 from reylejano/audit-roadmap
Initial External Security Audit Roadmap
2 parents 98b3d97 + 888e47d commit ce2fce9

File tree

1 file changed

+36
-0
lines changed

1 file changed

+36
-0
lines changed
Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
Past external security audits have not been comprehensive of the entire Kubernetes project.
2+
This roadmap lists previously audited focus areas and focus areas requested to be included in future audits.
3+
The Kubernetes community is invited to create issues and PRs to request additional components to be audited.
4+
5+
6+
| **Kubernetes Focus Area** | **Audit Year**| **Links** |
7+
|---------------------------|---------------|-----------|
8+
| Networking | 2019 | |
9+
| Cryptography | 2019 | |
10+
| Authentication & Authorization (including Role Based Access Controls) | 2019 | |
11+
| Secrets Management | 2019 | |
12+
| Multi-tenancy isolation: Specifically soft (non-hostile co-tenants) | 2019 | |
13+
| kube-apiserver | 2021 | |
14+
| kube-scheduler | 2021 | |
15+
| etcd (in the context of Kubernetes use of etcd) | 2021 | |
16+
| kube-controller-manager | 2021 | |
17+
| cloud-controller-manager | 2021 | |
18+
| kubelet | 2021 | https://github.com/kubernetes/kubelet https://github.com/kubernetes/kubernetes/tree/master/staging/src/k8s.io/kubelet |
19+
| kube-proxy | 2021 | https://github.com/kubernetes/kubernetes/tree/master/staging/src/k8s.io/kube-proxy https://github.com/kubernetes/kube-proxy |
20+
| secrets-store-csi-driver | 2021 | https://github.com/kubernetes-sigs/secrets-store-csi-driver |
21+
| cluster API | TBD | https://github.com/kubernetes-sigs/cluster-api |
22+
| kubectl | TBD | https://github.com/kubernetes/kubectl |
23+
| kubeadm | TBD | https://github.com/kubernetes/kubeadm |
24+
| metrics server | TBD | https://github.com/kubernetes-sigs/metrics-server
25+
| nginx-ingress (in the context of a Kubernetes ingress controller) | TBD | https://github.com/kubernetes/ingress-nginx
26+
| kube-state-metrics | TBD | https://github.com/kubernetes/kube-state-metrics
27+
| node feature discovery | TBD | https://github.com/kubernetes-sigs/node-feature-discovery
28+
| hierarchial namespace | TBD | https://github.com/kubernetes-sigs/multi-tenancy/tree/master/incubator/hnc
29+
| pod security policy replacement | TBD | https://github.com/kubernetes/enhancements/tree/master/keps/sig-auth/2579-psp-replacement
30+
| CoreDNS (in the context of Kubernetes use of CoreDNS) | TBD | Concept: https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/ Reference: https://kubernetes.io/docs/tasks/administer-cluster/dns-custom-nameservers/ |
31+
| cluster autoscaler | TBD | https://github.com/kubernetes/autoscaler/tree/master/cluster-autoscaler |
32+
| kube rbac proxy | TBD | https://github.com/brancz/kube-rbac-proxy |
33+
| kms plugins | TBD | https://kubernetes.io/docs/tasks/administer-cluster/kms-provider/#implementing-a-kms-plugin |
34+
| cni plugins | TBD | https://github.com/containernetworking/cni |
35+
| csi plugins | TBD | https://github.com/kubernetes-csi |
36+
| aggregator layer | TBD | https://github.com/kubernetes/kube-aggregator |

0 commit comments

Comments
 (0)