Guide
CIS Kubernetes hardening checklist
CIS Kubernetes benchmarks give platform teams a shared hardening language for GKE and EKS. Encode wins in Terraform so clusters stay compliant.
Checklist themes
- Control plane and API server exposure
- RBAC least privilege and service account hygiene
- Network policies and ingress boundaries
- Node image / OS hardening baselines
- Audit logging and secret management
- Workload security (pod security, image provenance)
Operationalize with IaC
Treat each CIS family as code modules and regression tests. Scan clusters and related cloud resources, run CIS-oriented compliance audits, then apply remediations through Terraform. Start with Orbour's compliance solution.