Post

[Kubernetes] CIS Benchmark์™€ kube-bench ์†Œ๊ฐœ

[Kubernetes] CIS Benchmark์™€ kube-bench ์†Œ๊ฐœ

๐Ÿ”’ CIS Kubernetes Benchmark์™€ kube-bench๋ž€?

์ฟ ๋ฒ„๋„คํ‹ฐ์Šค ํด๋Ÿฌ์Šคํ„ฐ์˜ ๋ณด์•ˆ ์ƒํƒœ๋ฅผ ์ ๊ฒ€ํ•˜๊ณ  ๊ทœ์ •์„ ์ค€์ˆ˜ํ•˜๊ธฐ ์œ„ํ•œ ๋„๊ตฌ์™€ ๊ธฐ์ค€์ž…๋‹ˆ๋‹ค.


1๏ธโƒฃ CIS๋ž€?

  • CIS (Center for Internet Security)
    • ์ „ ์„ธ๊ณ„์ ์œผ๋กœ ๋ณด์•ˆ ๋ฒค์น˜๋งˆํฌ์™€ ๊ฐ€์ด๋“œ๋ฅผ ์ œ๊ณตํ•˜๋Š” ๊ธฐ๊ด€
  • ์ฟ ๋ฒ„๋„คํ‹ฐ์Šค์šฉ CIS Kubernetes Benchmark
    • ํด๋Ÿฌ์Šคํ„ฐ ์„ค์ •์ด ๋ณด์•ˆ ๊ธฐ์ค€์„ ๋งŒ์กฑํ•˜๋Š”์ง€ ์ ๊ฒ€
    • ์ ๊ฒ€ ํ•ญ๋ชฉ ์˜ˆ: ์ธ์ฆ, RBAC, ๋„คํŠธ์›Œํฌ ์ •์ฑ…, etcd ์•”ํ˜ธํ™” ๋“ฑ

2๏ธโƒฃ kube-bench๋ž€?

  • kube-bench = CIS Kubernetes Benchmark ์ฒดํฌ ์ž๋™ํ™” ๋„๊ตฌ
  • ์ œ๊ณต: Aqua Security (aquasec/kube-bench)
  • ์—ญํ• :
    • ์ฟ ๋ฒ„๋„คํ‹ฐ์Šค ํด๋Ÿฌ์Šคํ„ฐ ๊ฒ€์‚ฌ
    • CIS ๊ธฐ์ค€ ์ค€์ˆ˜ ์—ฌ๋ถ€ ํ™•์ธ
    • ๋งˆ์Šคํ„ฐ/์›Œ์ปค ๋…ธ๋“œ, ์ปจํŠธ๋กค ํ”Œ๋ ˆ์ธ ๊ตฌ์„ฑ ์ฒดํฌ

3๏ธโƒฃ ์„ค์น˜ ๋ฐ ์‹คํ–‰ ์˜ˆ์‹œ

1
2
3
4
# Docker๋กœ ์‹คํ–‰
docker run --rm --net host --pid host --userns host \
  -v /etc:/etc:ro -v /var:/var:ro -v /usr/bin:/usr/local/bin:ro \
  aquasec/kube-bench:latest
  • ๊ฒ€์‚ฌ ๊ฒฐ๊ณผ: PASS / WARN / FAIL

    • PASS: ๋ณด์•ˆ ๊ธฐ์ค€ ์ค€์ˆ˜
    • WARN: ๊ถŒ์žฅํ•˜์ง€๋งŒ ํ•„์ˆ˜ ์•„๋‹˜
    • FAIL: ๋ณด์•ˆ ์œ„ํ—˜ ์กด์žฌ

4๏ธโƒฃ ์‚ฌ์šฉ ๋ชฉ์ 

  • ์ฟ ๋ฒ„๋„คํ‹ฐ์Šค ํด๋Ÿฌ์Šคํ„ฐ ๋ณด์•ˆ ์ ๊ฒ€
  • CIS Benchmark ๊ธฐ์ค€ ๊ทœ์ • ์ค€์ˆ˜ ํ™•์ธ
  • DevSecOps ํ™˜๊ฒฝ์—์„œ ์ž๋™ํ™”๋œ ๊ฐ์‚ฌ

5๏ธโƒฃ ์š”์•ฝ

ํ•ญ๋ชฉ๋‚ด์šฉ
CISCenter for Internet Security, ๋ณด์•ˆ ๋ฒค์น˜๋งˆํฌ ์ œ๊ณต ๊ธฐ๊ด€
kube-benchCIS Kubernetes Benchmark ์ž๋™ ๊ฒ€์‚ฌ ๋„๊ตฌ (AquaSec)
์šฉ๋„ํด๋Ÿฌ์Šคํ„ฐ ๋ณด์•ˆ ์ ๊ฒ€, ๊ทœ์ • ์ค€์ˆ˜ ํ™•์ธ, DevSecOps
์ถœ๋ ฅPASS / WARN / FAIL

๐Ÿ’ก ํ•œ ์ค„ ์š”์•ฝ: kube-bench = ์ฟ ๋ฒ„๋„คํ‹ฐ์Šค ํด๋Ÿฌ์Šคํ„ฐ๋ฅผ CIS ๋ณด์•ˆ ๊ธฐ์ค€์œผ๋กœ โ€œ๊ฑด๊ฐ•๊ฒ€์ง„โ€ ํ•ด์ฃผ๋Š” ๋„๊ตฌ

This post is licensed under CC BY 4.0 by the author.