Checks Performed
- An Admission Policy Engine Should Enforce Workload Policy
- Apply Security Context To Pods And Containers
- Audit Logging Should Be Enabled And Shipped Off-Cluster
- Automate GKE Version Management Using Release Channels
- Avoid Bindings To System:anonymous
- Avoid Non-Default Bindings To System:authenticated
- Avoid Non-Default Bindings To System:unauthenticated
- Avoid Use Of System:masters Group
- Configure Image Provenance Using ImagePolicyWebhook Admission Controller
- Consider External Secret Storage
- Consider Firewalling GKE Worker Nodes
- Consider GKE Sandbox For Running Untrusted Workloads
- Container Images Should Not Use The latest Or Untagged Tag
- Containers Should Define Liveness And Readiness Probes
- Containers Should Disallow Privilege Escalation
- Containers Should Drop All Linux Capabilities
- Containers Should Not Run In Privileged Mode
- Containers Should Run As Non-Root
- Containers Should Set CPU And Memory Limits
- Containers Should Set CPU And Memory Requests
- Containers Should Use A Read-Only Root Filesystem
- Create Administrative Boundaries Between Resources Using Namespaces
- Enable Customer-Managed Encryption Keys (CMEK) For Boot Disks
- Enable Customer-Managed Encryption Keys (CMEK) For GKE Persistent Disks
- Enable Linux Auditd Logging
- Enable Security Posture
- Enable VPC Flow Logs And Intranode Visibility
- Enforce Pod Security Standard Baseline Profile Or Stricter For All Namespaces
- Ensure All Namespaces Have Network Policies Defined
- Ensure Authentication Using Client Certificates Is Disabled
- Ensure Cluster-Admin Role Is Only Used Where Required
- Ensure Clusters Are Created With Private Endpoint Enabled And Public Access Disabled
- Ensure Clusters Are Created With Private Nodes
- Ensure Container-Optimized OS Is Used For GKE Node Images
- Ensure Control Plane Authorized Networks Is Enabled
- Ensure Default Service Accounts Are Not Actively Used
- Ensure GKE Clusters Are Not Running Using The Compute Engine Default Service Account
- Ensure Image Vulnerability Scanning Is Enabled
- Ensure Integrity Monitoring For Shielded GKE Nodes Is Enabled
- Ensure Kube-Proxy Kubeconfig File Ownership Is Set To root:root
- Ensure Kube-Proxy Kubeconfig File Permissions Are 644 Or More Restrictive
- Ensure Kubelet Configuration File Ownership Is Set To root:root
- Ensure Kubelet Configuration File Permissions Are Set To 644
- Ensure Kubernetes Secrets Are Encrypted Using Keys Managed In Cloud KMS
- Ensure Kubernetes Web UI Is Disabled
- Ensure Legacy Authorization (ABAC) Is Disabled
- Ensure Logging And Cloud Monitoring Is Enabled
- Ensure Node Auto-Repair Is Enabled For GKE Nodes
- Ensure Node Auto-Upgrade Is Enabled For GKE Nodes
- Ensure Only Trusted Container Images Are Used
- Ensure Secure Boot For Shielded GKE Nodes Is Enabled
- Ensure Service Account Tokens Are Only Mounted Where Necessary
- Ensure Shielded GKE Nodes Are Enabled
- Ensure That Alpha Clusters Are Not Used For Production Workloads
- Ensure The CNI In Use Supports Network Policies
- Ensure The GKE Metadata Server Is Enabled
- Ensure The Seccomp Profile Is Set To RuntimeDefault In Pod Definitions
- Ensure Use Of Google-Managed SSL Certificates
- Ensure Use Of VPC-Native Clusters
- Every Non-System Namespace Should Have A Default-Deny NetworkPolicy
- Limit Use Of The Bind, Impersonate And Escalate Permissions
- Manage Kubernetes RBAC Users With Google Groups For GKE
- Minimize Access To Secrets
- Minimize Cluster Access To Read-Only For Container Image Repositories
- Minimize User Access To Container Image Repositories
- Minimize Wildcard Use In Roles And ClusterRoles
- Multi-Replica Deployments Should Have A PodDisruptionBudget
- Mutable Image Tags Should Use imagePullPolicy Always
- Namespaces Should Enforce Pod Security Admission Baseline Or Stricter
- No RoleBinding Should Grant Access To Anonymous Or Unauthenticated Users
- No ServiceAccount Should Be Bound To cluster-admin
- No Workloads Should Run In The default Namespace
- Pods Should Be Managed By A Controller
- Pods Should Not Mount HostPath Volumes
- Pods Should Not Share Host Namespaces
- Pods That Do Not Use The API Should Disable Token Automount
- pods/exec Should Not Be Granted To Broad Subjects
- Prefer Bound Projected ServiceAccount Tokens Over Secret Tokens
- Prefer Using Dedicated GCP Service Accounts And Workload Identity
- Prefer Using Secrets As Files Over Secrets As Environment Variables
- Secrets Should Be Encrypted At Rest
- Sensitive Values Should Not Be Passed As Literal Env Vars
- Tenant Namespaces Should Have A ResourceQuota
- The Default Namespace Should Not Be Used

