Guide

CIS Kubernetes hardening checklist

CIS Kubernetes benchmarks give platform teams a shared hardening language for GKE and EKS. Encode wins in Terraform so clusters stay compliant.

Checklist themes

  • Control plane and API server exposure
  • RBAC least privilege and service account hygiene
  • Network policies and ingress boundaries
  • Node image / OS hardening baselines
  • Audit logging and secret management
  • Workload security (pod security, image provenance)

Operationalize with IaC

Treat each CIS family as code modules and regression tests. Scan clusters and related cloud resources, run CIS-oriented compliance audits, then apply remediations through Terraform. Start with Orbour's compliance solution.