Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
59 commits
Select commit Hold shift + click to select a range
fd73a32
Upgrade elastic-operator to version 3.0.0
svalenciah19 Jun 26, 2025
9bee353
Upgrade elastic-stack to version 0.15.0
svalenciah19 Jul 15, 2025
ae44cdd
Merge branch 'main' into main
vishwanaths Jul 30, 2025
2b3fcce
Merge branch 'main' into main
vishwanaths Aug 1, 2025
e632f8e
Merge branch 'main' into main
vishwanaths Sep 4, 2025
2960a99
Upgrade pack elastic-operator to version 3.1.0
svalenciah19 Sep 15, 2025
3535067
Upgrade pack elastic-stack to version 0.16.0
svalenciah19 Sep 18, 2025
6ec9345
Merge branch 'spectrocloud:main' into main
svalenciah19 Sep 22, 2025
bc5f1d0
Merge branch 'main' into main
vishwanaths Oct 7, 2025
5482192
Upgrade elastick-operator pack to version 3.2.0
svalenciah19 Nov 4, 2025
1fc1ecc
Upgrade elastic-stack pack to version 0.17.0
svalenciah19 Nov 6, 2025
ede1ae8
Upgrade crossplane pack to version 2.1.0
svalenciah19 Nov 12, 2025
82d2968
add constraints pack
svalenciah19 Nov 14, 2025
03fec7e
Merge branch 'main' into main
vishwanaths Nov 18, 2025
a2b4e04
Upgrade crossplane pack to v2.1.3
svalenciah19 Dec 11, 2025
95d40cc
Merge branch 'main' into main
vishwanaths Feb 6, 2026
c399c0a
Upgrade pack elastic-operator to 3.3.0
svalenciah19 Feb 11, 2026
1ec5fdb
Upgrade pack elastic-stack pack to 0.18.0
svalenciah19 Feb 11, 2026
a7c8e87
add references pack
svalenciah19 Feb 11, 2026
d42c557
Change README
svalenciah19 Feb 11, 2026
c08ee80
Change README 2.0
svalenciah19 Feb 11, 2026
b9c02d9
Complement README
svalenciah19 Feb 11, 2026
027b70e
Merge branch 'PAC-3711'
svalenciah19 Feb 11, 2026
eff21e1
Merge branch 'spectrocloud:main' into main
svalenciah19 Feb 19, 2026
d709a2a
add tag latest pack image curl
svalenciah19 Feb 24, 2026
57d0064
Merge remote-tracking branch 'origin/PAC-3711'
svalenciah19 Feb 24, 2026
2b67595
Merge branch 'spectrocloud:main' into main
svalenciah19 Mar 17, 2026
64320dc
Upgrade elastic-operator pack to 3.3.1
svalenciah19 Mar 17, 2026
6042c11
Upgrade elastic-stack pack to 0.18.1
svalenciah19 Mar 17, 2026
86cea26
Merge branch 'PAC-3852'
svalenciah19 Mar 17, 2026
23973f0
Merge branch 'spectrocloud:main' into main
svalenciah19 Apr 9, 2026
6dd971d
Merge branch 'main' of https://github.com/svalenciah19/pack-central
svalenciah19 Apr 9, 2026
e3f2d37
Upgrade fluentbit pack to 5.0.0
svalenciah19 Apr 10, 2026
bc27247
change branch delete PR fluentbit-5.0.0
svalenciah19 Apr 14, 2026
f3e5f96
PAC-3914 Upgrade fluentbit pack to 5.0.0
svalenciah19 Apr 14, 2026
76bfcbe
Delete trust-policy.json
vishwanaths Apr 16, 2026
55c7e6b
Merge branch 'spectrocloud:main' into main
svalenciah19 Apr 28, 2026
a40bb92
PAC-4026 Upgrade crossplane pack to 2.2.1
svalenciah19 Apr 28, 2026
f8fab80
Merge branch 'main' into main
vishwanaths May 7, 2026
6ce11a1
Merge branch 'spectrocloud:main' into main
svalenciah19 May 21, 2026
9234225
PAC-4128 - Upgrade csi-trident pack to 26.02.1
svalenciah19 May 26, 2026
bf530a6
Merge branch 'main' into main
vishwanaths May 26, 2026
02ba585
Merge branch 'spectrocloud:main' into main
svalenciah19 Jun 2, 2026
eb707b4
Upgrade strimzi-kafka-operator pack to 1.0.0
svalenciah19 Jun 2, 2026
c36e79f
Merge branch 'spectrocloud:main' into main
svalenciah19 Jun 9, 2026
9e8f97d
Merge branch 'spectrocloud:main' into main
svalenciah19 Jun 17, 2026
94d7d62
Upgrade thanos pack to 17.6.0
svalenciah19 Jun 19, 2026
d089b3f
Upgrade kyverno pack to 1.18.1
svalenciah19 Jul 2, 2026
f374b6c
Merge branch 'spectrocloud:main' into main
svalenciah19 Jul 2, 2026
0a7ad61
Upgrade sonobuoy pack to 0.57.5
svalenciah19 Jul 14, 2026
2125d8e
Upgrade cert-manager pack to 1.21.0
svalenciah19 Jul 18, 2026
ede40ac
deleted: packs/cert-manager-1.21.0/README.md
svalenciah19 Jul 22, 2026
3b62cab
Merge branch 'spectrocloud:main' into main
svalenciah19 Jul 30, 2026
076fab9
Merge branch 'spectrocloud:main' into main
svalenciah19 Aug 20, 2026
86229cc
Update kubebench pack to 1.16.0
svalenciah19 Aug 20, 2026
171511f
Changes kubebench-0.16.0
svalenciah19 Aug 21, 2026
45b47f0
add change values.yaml
svalenciah19 Aug 21, 2026
b0d7ca1
add content.image pack
svalenciah19 Aug 25, 2026
9f1c9d3
Merge branch 'main' into kubebench-1.16.0
svalenciah19 Aug 25, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
106 changes: 106 additions & 0 deletions packs/cks-kubebench-0.16.0/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,106 @@
# Kube-bench

Kube-bench is an open-source tool developed by Aqua Security that checks whether Kubernetes is deployed according to the CIS Kubernetes Benchmark recommendations.
The tool performs automated security checks against Kubernetes components and node configuration, generating findings categorized as PASS, FAIL, WARN, and INFO.
This addon deploys kube-bench as a Kubernetes Job and performs a one-time security assessment of the cluster.

## Prerequisites

* Kubernetes 1.29 or later.
* Permissions to create and execute Kubernetes Jobs.
* Worker nodes must allow the hostPath mounts required by kube-bench.

> **Note:**
> Managed Kubernetes services such as Amazon EKS, Azure AKS, and Google GKE may restrict access to certain control plane components. As a result, some benchmark checks may be skipped or reported differently compared to self-managed Kubernetes environments.

Kube-bench requires access to host filesystem paths in order to inspect Kubernetes node configuration and evaluate CIS benchmark compliance.

## Parameters

| Name | Description | Type | Default Value | Required |
| ---------------- | --------------------------------------------- | ------ | ------------------ | -------- |
| image.repository | Container image repository used by kube-bench | string | aquasec/kube-bench | Yes |
| image.tag | kube-bench image version | string | v0.16.0 | Yes |

## Upgrade

Upgrade from previous versions of this addon is supported.

## Usage

After installation, verify that the Job has been created successfully:

```sh
kubectl get jobs -A
```

Verify that the Pod associated with the Job has been created:

```sh
kubectl get pods -A | grep kube-bench
```

Once the Job has completed, retrieve the benchmark results:

```sh
kubectl logs job/kube-bench
```

The output contains CIS benchmark findings similar to:

```text
PASS
FAIL
WARN
INFO
```

## Validation

### Verify Job Completion

```sh
kubectl get jobs -A
```

Expected result:

```text
NAME COMPLETIONS DURATION AGE
kube-bench 1/1 <time> <age>
```

### Verify Pod Status

```sh
kubectl get pods -A | grep kube-bench
```

Expected result:

```text
STATUS
Completed
```

### Verify Benchmark Results

```sh
kubectl logs job/kube-bench
```

Expected output contains one or more of the following result types:

```text
PASS
FAIL
WARN
INFO
```

These results indicate that kube-bench successfully executed the CIS benchmark checks against the cluster.

## References

* https://github.com/aquasecurity/kube-bench
* https://aquasecurity.github.io/kube-bench/
Binary file added packs/cks-kubebench-0.16.0/logo.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
91 changes: 91 additions & 0 deletions packs/cks-kubebench-0.16.0/manifests/job.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,91 @@
---
apiVersion: batch/v1
kind: Job
metadata:
name: kube-bench
spec:
template:
metadata:
labels:
app: kube-bench
spec:
containers:
- command: [ "kube-bench" ]
image: docker.io/aquasec/kube-bench:v0.16.0
name: kube-bench
volumeMounts:
- name: var-lib-cni
mountPath: /var/lib/cni
readOnly: true
- mountPath: /var/lib/etcd
name: var-lib-etcd
readOnly: true
- mountPath: /var/lib/kubelet
name: var-lib-kubelet
readOnly: true
- mountPath: /var/lib/kube-scheduler
name: var-lib-kube-scheduler
readOnly: true
- mountPath: /var/lib/kube-controller-manager
name: var-lib-kube-controller-manager
readOnly: true
- mountPath: /etc/systemd
name: etc-systemd
readOnly: true
- mountPath: /lib/systemd/
name: lib-systemd
readOnly: true
- mountPath: /srv/kubernetes/
name: srv-kubernetes
readOnly: true
- mountPath: /etc/kubernetes
name: etc-kubernetes
readOnly: true
- mountPath: /usr/local/mount-from-host/bin
name: usr-bin
readOnly: true
- mountPath: /etc/cni/net.d/
name: etc-cni-netd
readOnly: true
- mountPath: /opt/cni/bin/
name: opt-cni-bin
readOnly: true
hostPID: true
restartPolicy: Never
volumes:
- name: var-lib-cni
hostPath:
path: /var/lib/cni
- hostPath:
path: /var/lib/etcd
name: var-lib-etcd
- hostPath:
path: /var/lib/kubelet
name: var-lib-kubelet
- hostPath:
path: /var/lib/kube-scheduler
name: var-lib-kube-scheduler
- hostPath:
path: /var/lib/kube-controller-manager
name: var-lib-kube-controller-manager
- hostPath:
path: /etc/systemd
name: etc-systemd
- hostPath:
path: /lib/systemd
name: lib-systemd
- hostPath:
path: /srv/kubernetes
name: srv-kubernetes
- hostPath:
path: /etc/kubernetes
name: etc-kubernetes
- hostPath:
path: /usr/bin
name: usr-bin
- hostPath:
path: /etc/cni/net.d/
name: etc-cni-netd
- hostPath:
path: /opt/cni/bin/
name: opt-cni-bin
17 changes: 17 additions & 0 deletions packs/cks-kubebench-0.16.0/pack.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
{
"addonType": "security",
"annotations": {
"source": "community",
"contributor" : "spectrocloud"
},
"kubeManifests": [
"manifests/job.yaml"
],
"cloudTypes": [
"all"
],
"displayName": "Kubebench",
"layer":"addon",
"name": "kubebench",
"version": "0.16.0"
}
5 changes: 5 additions & 0 deletions packs/cks-kubebench-0.16.0/values.yaml
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
pack:
namespace: "kube-bench"
content:
images:
- image: docker.io/aquasec/kube-bench:v0.16.0
Loading