This is your work, valued
container-security-checklist. Checklist for container security - devsecops practices
★ 1.6kdevsecops-resources. A list of resources blogs talks material about DevSecOps
★ 104workshop-cloud-native-security. workshop about cloud-native security
★ 69kubernetes-security-checklist. Awesome resources about Security in Kubernetes
★ 49demo-fileless. Go
★ 12demo-trivy. demo-trivy
★ 9krol3.
★ 7k8s-auditing. kubernetes auditing playground
★ 4trivy. A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable for CI
★ 3demo-infra-code. HCL
★ 3container_go. Container with Golang
★ 2go-cowsay. Go
★ 2demo-trivy-postee. demo using trivy and postee
★ 2cncf-translations-utils. CNCF translations utils for the Spanish group team
★ 2k8s-vaults. kubernetes using vaults
★ 2k8s_security. k8s_security
★ 1csp-samples. Aqua CSP samples
★ 1WebGoat. WebGoat is a deliberately insecure application
★ 1java-docker. Java docker sample
★ 1azch-captureorder. The Capture Order API
★ 1kube-bench. Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark
★ 1docker-k8s-101. Hello world in docker and kubernetes - 101
★ 1nginx-ansible-molecule. Playbook to install nginx and molecule to test
★ 1docker-samples. docker web basic applications
★ 1app-jenkinsfile-k8s. Sample app using jenkinsfile and kubernetes
★ 1python-flask. simple microservice
★ 1prom-restify-api-nodejs. simple demo restify api in nodejs
★ 1signalhound. Signalhound monitors TestGrid dashboards to identify and summarize test failures and flaking patterns in Kubernetes CI/CD pipelines.
★ 10cloud-provider-kind. Cloud provider for KIND clusters
★ 488memorials. 🕯️💐CNCF Community Memorials
★ 196crd-to-sample-yaml. Generate a sample YAML file from a CRD and view it rendered on a nice website
★ 198communitygroups. 👩🏿💻👨🏿💻👩🏾💻👨🏾💻👩🏽💻👨🏽💻👩🏼💻👨🏼💻👩🏻💻👨🏻💻CNCF Community Groups (formerly meetups)
★ 220calico. Cloud native networking and network security
★ 7.3kelastic-container. Stand up a simple Elastic container with Kibana, Fleet, and the Detection Engine
★ 568awesome-cicd-attacks. Practical resources for offensive CI/CD security research. Curated the best resources I've seen since 2021.
★ 616MinikubeWindowsContainers. This repo describes the steps for a prototype of Windows on MiniKube
★ 45cloudsec-ninja. Become a CloudSecurity Engineer using the AWS Cloud for free. ☁️🔐🥷
★ 160httpbin. HTTP Request & Response Service, written in Python + Flask.
★ 14kkubeadm-scripts. Scripts & Kubernetes manifests for Kubeadm Kubernetes cluster setup
★ 272pyroscope. Continuous Profiling Platform. Debug performance issues down to a single line of code
★ 12kreaper. Live validation proxy tool for testing web app vulnerabilities
★ 878BioDrop. Connect to your audience with a single link. Showcase the content you create and your projects in one place. Make it easier for people to find, follow and subscribe.
★ 5.7klearning-ebpf. Learning eBPF, published by O'Reilly - out now! Here's where you'll find a VM config for the examples, and more
★ 1.8kwebsite. Kubernetes website and documentation repo:
★ 5.3kcapsule. Multi-tenancy and policy-based framework for Kubernetes.
★ 2.1kmorningpost. A project template for a personalised newspaper in Go
★ 9cilium. eBPF-based Networking, Security, and Observability
★ 25kall-things-advocacy. Conference talks, podcasts, speaking engagements...oh my!
★ 7grace. :screwdriver: It's strace, with colours.
★ 284topaz. Cloud-native authorization for modern applications and APIs
★ 1.4kguac. GUAC aggregates software security metadata into a high fidelity graph database.
★ 1.5kdemo-fileless. Go
★ 12ebpf-slide. Collection of Linux eBPF slides/documents.
★ 981gitjacker. 🔪 :octocat: Leak git repositories from misconfigured websites
★ 1.6klazytrivy. Vulnerability scanning just got lazier
★ 326ThreatMapper. Open Source Cloud Native Application Protection Platform (CNAPP)
★ 5.3kchain-bench. An open-source tool for auditing your software supply chain stack for security compliance based on a new CIS Software Supply Chain benchmark.
★ 774trivy-operator. Kubernetes-native security toolkit
★ 1.9kcloudquery. Data pipelines for cloud config and security data. Build cloud asset inventory, CSPM, FinOps, and vulnerability management solutions. Extract from AWS, Azure, GCP, and 70+ cloud and SaaS sources.
★ 6.5ktrivy-action. Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities
★ 1.4kCVE-2022-0847. The Dirty Pipe Vulnerability
★ 46settingLimitsToContainers. You should be setting limits to your Linux containers.
★ 2defsec. Trivy's misconfiguration scanning engine
★ 214csp-integration-samples. Aqua CSP integrations Samples
★ 1vulnerability-operator. Scans SBOMs for vulnerabilities with Grype
★ 88security-review.
★ 17terraform-provider-aquasec. The Aqua Security Provider for Terraform allows you to declaratively define the configuration of your Aqua platform.
★ 37workshop-cloud-native-security. workshop about cloud-native security
★ 69peridot. Developer machine management for Linux/OSX. Think Terraform/Ansible for your dotfiles/packages! :gear::house:
★ 21developers-conferences-agenda. developers.events is a community-driven platform listing developer/tech conferences and Calls for Papers (CFPs) worldwide with a list, a calendar and a map view. It helps organizers, speakers, sponsors & attendees.
★ 2kkubescape. Kubescape is an open-source Kubernetes security platform for your IDE, CI/CD pipelines, and clusters. It includes risk analysis, security, compliance, and misconfiguration scanning, saving Kubernetes users and administrators precious time, effort, and resources.
★ 12kbuild-security-action. GitHub Action for Aqua Build Security
★ 8gifski. GIF encoder based on libimagequant (pngquant). Squeezes maximum possible quality from the awful GIF format.
★ 5.6ktfsec-pr-commenter-action. Add comments to pull requests where tfsec checks have failed
★ 171cloud-metadata. Common metadata repository for CSPM and TFSec checks
★ 10docker-bench-security. The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.
★ 9.7kDescomplicandoDocker. Descomplicando o Docker, o livro.
★ 3.4klinux-insides. A book-in-progress about the Linux kernel and its insides.
★ 33klibbpfgo. eBPF library for Go. Powered by libbpf.
★ 844container-security-checklist. Checklist for container security - devsecops practices
★ 1.6kbtfhub. BTFhub, in collaboration with the BTFhub Archive repository, supplies BTF files for all published kernels that lack native support for embedded BTF. This joint effort ensures that even kernels without built-in BTF support can effectively leverage the benefits of eBPF programs, promoting compatibility across various kernel versions.
★ 481tracee-action. Protect GitHub Actions with Tracee
★ 81samples. Learn how to develop with Okteto
★ 110aqua-dash. Sample Aqua CSP dashboard
★ 8saas-api-samples. Sample code snippets for consuming the CloudSploit API
★ 13tfsec. Tfsec is now part of Trivy
★ 7kdevops-exercises. Linux, Jenkins, AWS, SRE, Prometheus, Docker, Python, Ansible, Git, Kubernetes, Terraform, OpenStack, SQL, NoSQL, Azure, GCP, DNS, Elastic, Network, Virtualization. DevOps Interview Questions
★ 84klibbpf. Automated upstream mirror for libbpf stand-alone build.
★ 2.7ktrivy-plugin-kubectl. A Trivy plugin that scans the images of a kubernetes resource
★ 25terrascan. Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.
★ 5.2kappshield. Security configuration checks for popular cloud native applications and infrastructure.
★ 119litmus. Litmus helps SREs and developers practice chaos engineering in a Cloud-native way. Chaos experiments are published at the ChaosHub (https://hub.litmuschaos.io). Community notes is at https://hackmd.io/a4Zu_sH4TZGeih-xCimi3Q
★ 5.6kharbor-scanner-trivy. Use Trivy as a plug-in vulnerability scanner in the Harbor registry
★ 227docker-bench. Checks whether Docker is deployed according to security best practices as defined in the CIS Docker Benchmark
★ 223linux-bench. Checks whether a Linux server according to security best practices as defined in the CIS Distribution-Independent Linux Benchmark
★ 188fanal. Static Analysis Library for Containers
★ 196simulator. Kubernetes Security Training Platform - focusing on security mitigation
★ 999kube-query. [EXPERIMENTAL] Extend osquery to report on Kubernetes
★ 228tag-contributor-strategy. CNCF Technical Advisory Group on Contributor Strategy -- maintainer relations, building up contributors, governance, graduation, and more.
★ 209starboard-lens-extension. Lens extension for viewing Starboard security information
★ 116binfinder. Find binary files not installed through package manager
★ 11Certified-Kubernetes-Security-Specialist. Curated resources help you prepare for the CNCF/Linux Foundation CKS 2021 "Kubernetes Certified Security Specialist" Certification exam. Please provide feedback or requests by raising issues, or making a pull request. All feedback for improvements are welcome. thank you.
★ 2.1klearn-go-with-tests. Learn Go with test-driven development
★ 24kcontained.af. A stupid game for learning about containers, capabilities, and syscalls.
★ 909kubepug. Kubernetes PreUpGrade (Checker)
★ 1.8kkubedoom. Kill Kubernetes pods by playing Id's DOOM!
★ 2.2kconftest. Write tests against structured configuration data using the Open Policy Agent Rego query language
★ 3.2kFree_CyberSecurity_Professional_Development_Resources. An awesome list of FREE resources for training, conferences, speaking, labs, reading, etc that are free. Originally built during COVID-19 for cybersecurity professionals with downtime can take advantage of to improve their skills and marketability to come out on the other side ready to rock. Now its taken on a life of its own and will persist, COVID be damned.
★ 2.2kpixie. Instant Kubernetes-Native Application Observability
★ 6.5ksecurity-profiles-operator. The Kubernetes Security Profiles Operator
★ 860cloud-native-bpf-workshop. Shell
★ 92cloud-native-security-tutorial. Getting Started With Cloud Native Security
★ 71app-2025. Use architecture patterns from the future to build on AWS today!
★ 70starboard-operator. The Starboard Operator has moved to the main Starboard repo, and this one is being retired
★ 16starboard-octant-plugin. Octant plugin for viewing Starboard security information
★ 56kubectl-neat. Clean up Kubernetes yaml and json output to make it readable
★ 2.1klearngo. ❤️ 1000+ Hand-Crafted Go Examples, Exercises, and Quizzes. 🚀 Learn Go by fixing 1000+ tiny programs.
★ 20kCKA-StudyGuide. Study guide for the CKA exam
★ 1.4kcka. Resources to get ready for CKA exam
★ 67cloudsploit. Cloud Security Posture Management (CSPM)
★ 3.8kkubectl-who-can. Show who has RBAC permissions to perform actions on different resources in Kubernetes
★ 917kube-hunter. Hunt for security weaknesses in Kubernetes clusters
★ 5.1kkube-bench. Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark
★ 8.1ktracee. Linux Runtime Security and Forensics using eBPF
★ 4.6kshipper. Kubernetes native multi-cluster canary or blue-green rollouts using Helm
★ 729go-tutor. Golang exercises and solutions
★ 2kubicorn. Simple, cloud native infrastructure for Kubernetes.
★ 1.7k