|
| 1 | +Past external security audits have not been comprehensive of the entire Kubernetes project. |
| 2 | +This roadmap lists previously audited focus areas and focus areas requested to be included in future audits. |
| 3 | +The Kubernetes community is invited to create issues and PRs to request additional components to be audited. |
| 4 | + |
| 5 | + |
| 6 | +| **Kubernetes Focus Area** | **Audit Year**| **Links** | |
| 7 | +|---------------------------|---------------|-----------| |
| 8 | +| Networking | 2019 | | |
| 9 | +| Cryptography | 2019 | | |
| 10 | +| Authentication & Authorization (including Role Based Access Controls) | 2019 | | |
| 11 | +| Secrets Management | 2019 | | |
| 12 | +| Multi-tenancy isolation: Specifically soft (non-hostile co-tenants) | 2019 | | |
| 13 | +| kube-apiserver | 2021 | | |
| 14 | +| kube-scheduler | 2021 | | |
| 15 | +| etcd (in the context of Kubernetes use of etcd) | 2021 | | |
| 16 | +| kube-controller-manager | 2021 | | |
| 17 | +| cloud-controller-manager | 2021 | | |
| 18 | +| kubelet | 2021 | https://github.com/kubernetes/kubelet https://github.com/kubernetes/kubernetes/tree/master/staging/src/k8s.io/kubelet | |
| 19 | +| kube-proxy | 2021 | https://github.com/kubernetes/kubernetes/tree/master/staging/src/k8s.io/kube-proxy https://github.com/kubernetes/kube-proxy | |
| 20 | +| secrets-store-csi-driver | 2021 | https://github.com/kubernetes-sigs/secrets-store-csi-driver | |
| 21 | +| cluster API | TBD | https://github.com/kubernetes-sigs/cluster-api | |
| 22 | +| kubectl | TBD | https://github.com/kubernetes/kubectl | |
| 23 | +| kubeadm | TBD | https://github.com/kubernetes/kubeadm | |
| 24 | +| metrics server | TBD | https://github.com/kubernetes-sigs/metrics-server |
| 25 | +| nginx-ingress (in the context of a Kubernetes ingress controller) | TBD | https://github.com/kubernetes/ingress-nginx |
| 26 | +| kube-state-metrics | TBD | https://github.com/kubernetes/kube-state-metrics |
| 27 | +| node feature discovery | TBD | https://github.com/kubernetes-sigs/node-feature-discovery |
| 28 | +| hierarchial namespace | TBD | https://github.com/kubernetes-sigs/multi-tenancy/tree/master/incubator/hnc |
| 29 | +| pod security policy replacement | TBD | https://github.com/kubernetes/enhancements/tree/master/keps/sig-auth/2579-psp-replacement |
| 30 | +| CoreDNS (in the context of Kubernetes use of CoreDNS) | TBD | Concept: https://kubernetes.io/docs/concepts/services-networking/dns-pod-service/ Reference: https://kubernetes.io/docs/tasks/administer-cluster/dns-custom-nameservers/ | |
| 31 | +| cluster autoscaler | TBD | https://github.com/kubernetes/autoscaler/tree/master/cluster-autoscaler | |
| 32 | +| kube rbac proxy | TBD | https://github.com/brancz/kube-rbac-proxy | |
| 33 | +| kms plugins | TBD | https://kubernetes.io/docs/tasks/administer-cluster/kms-provider/#implementing-a-kms-plugin | |
| 34 | +| cni plugins | TBD | https://github.com/containernetworking/cni | |
| 35 | +| csi plugins | TBD | https://github.com/kubernetes-csi | |
| 36 | +| aggregator layer | TBD | https://github.com/kubernetes/kube-aggregator | |
0 commit comments