← All bundles
</> Policy bundle · Apache-2.0

cenroq-best-practices

versionv0.2.0 policies176 bindings528 licenseApache-2.0

Best practice validating admission bundle that enforces pod hardening, safer runtime defaults, and broader cluster guardrails (RBAC, secrets, exposure, and risky config restrictions) for a strong security baseline.

// install

apply the bundle.

$ kubeapt bundles install cenroq-best-practices

…or download and apply it with kubectl alone:

mkdir -p /tmp/cenroq && curl -L https://github.com/cenroq/kubernetes-security-policies/releases/download/vap_cenroq-best-practices%40v0.2.0/cenroq-best-practices_v0.2.0.tar.gz | tar -xz -C /tmp/cenroq && kubectl apply -f /tmp/cenroq/cenroq-best-practices/policies.yaml -f /tmp/cenroq/cenroq-best-practices/bindings.yaml

Archives: cenroq-best-practices_v0.2.0.tar.gz · cenroq-best-practices_v0.2.0.zip

// activation

warn, audit, then enforce.

Nothing is enforced until you label a namespace. Move one namespace at a time, and start with warn.

To exclude a single policy from a mode, label the namespace <policy-name>.security.cenroq.io/warn=disabled.

// contents

176 policies in this bundle.

Each links to its page in the policy catalog.