CIS Google Kubernetes Engine (GKE) Benchmark

XEIZE supports major IaC checks related to the CIS Google Kubernetes Engine (GKE) Benchmark.

Main areas covered

Section Area Description
1 Cluster setup Private Cluster, Shielded Nodes, Master Authorized Networks, and restrictions on default service account use
2 Logging Cloud Logging and Monitoring integration
3 Cluster hardening Disabling legacy authorization and basic authentication, NetworkPolicy, and restrictions on outdated versions
4 Worker node pools Auto-upgrade, Auto-repair, Shielded VM, and Shielded Nodes
5 Policies Least-privilege RBAC, Secret management, and Pod Security Standards

References