Search
Kubernetes · Authorization and RBAC
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes. | Cybereason-Public/ | 280 | 12 repos | ~2k | Automated safety check: Pass | GPL-2.0 | 3 days ago |
| 2 | Creates and queries KubeSphere users, workspaces and projects and assigns built-in roles, defaulting to least privilege and never deleting anything. | kubesphere/ | 17k | — | ~3.1k | Automated safety check: Pass | Unknown | 2 mo ago |
| 3 | Help users install and configure the mirrord Operator for team/enterprise environments. | metalbear-co/ | 5.4k | 1 repo | ~4.6k | Automated safety check: Pass | MIT | today |
| 4 | Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps. | Jeffallan/ | 12k | 1 repo | ~2.1k | Automated safety check: Pass | MIT | 8 days ago |
| 5 | How Kopiur writes and maintains user-facing docs — the MkDocs Material site under docs/ and the example manifests under deploy/examples/. | home-operations/ | 115 | — | ~2.5k | Automated safety check: Pass | AGPL-3.0 | today |
| 6 | Kubernetes workload patterns, resource management, RBAC, probes, autoscaling, ConfigMap/Secret handling, and kubectl debugging for production-grade deployments. | timothywarner-org/ | 224 | — | ~4.5k | Automated safety check: Pass | MIT | 2 mo ago |
| 7 | Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access. | vinayaklatthe/ | 175 | — | ~2.2k | Automated safety check: Pass | MIT | 3 mo ago |
| 8 | Kubernetes workload patterns, resource management, RBAC, probes, autoscaling, ConfigMap/Secret handling, and kubectl debugging for production-grade deployments. | affaan-m/ | 277k | 1 repo | ~5k | Automated safety check: Pass | MIT | today |
| 9 | Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and… | hardw00t/ | 105 | — | ~2.8k | Automated safety check: Pass | No licence | 5 mo ago |
| 10 | 10.Policy Opa Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA). | AgentSecOps/ | 220 | 1 repo | ~3.5k | Automated safety check: Pass | Unknown | 5 mo ago |
| 11 | Detects and prevents privilege escalation inside Kubernetes pods by combining admission control (OPA policies), runtime monitoring (Falco), and audit log analysis of security contexts, Linux… | mukul975/ | 34k | — | ~2.4k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 12 | Hardens Kubernetes RBAC by designing least-privilege Roles and ClusterRoles, auditing RoleBindings, eliminating cluster-admin sprawl, separating service accounts, and integrating an external OIDC… | mukul975/ | 34k | — | ~2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 13 | Assesses the security posture of the etcd cluster backing Kubernetes: encryption at rest, TLS peer and client transport, access control, backup encryption, and network isolation. | mukul975/ | 34k | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 14 | Evaluates Kubernetes cluster security by actively simulating attacker techniques against the API server, kubelet, etcd, pods, RBAC, network policy, and secrets, using kube-hunter, Kubescape… | mukul975/ | 34k | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 15 | Parses Kubernetes API server audit logs (JSON lines) to detect exec-into-pod, secret access, RBAC modifications, privileged pod creation, and anonymous API access, and builds SIEM detection rules… | mukul975/ | 34k | — | ~654 | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 16 | Finds over-permissive RBAC roles and service-account token abuse paths in a Kubernetes cluster using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess, tracing which subjects can… | mukul975/ | 34k | — | ~3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 17 | Hardens managed Kubernetes clusters on EKS, AKS, and GKE by implementing Pod Security Standards, network policies, workload identity (IRSA for EKS, Workload Identity for GKE, Managed Identities for… | mukul975/ | 34k | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | 1 mo ago |
| 18 | Operating production Kubernetes clusters effectively with resource management, advanced scheduling, networking, storage, security hardening, and autoscaling. | ancoleman/ | 525 | — | ~3.6k | Automated safety check: Pass | MIT | 10 mo ago |
| 19 | Plans and configures multi-tenancy on GKE. An agent skill from google/skills. | google/ | 21k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 20 | Plans, configures, and hardens platform-level Google Kubernetes Engine (GKE) cluster security. | google/ | 21k | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 21 | Configures and diagnoses Workload Identity Federation for GKE authentication failures for Pods (403 "iam.serviceAccounts.getAccessToken" / permission denied, "could not find default credentials", or… | google/ | 21k | — | ~4.4k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 22 | Generate/create/scaffold Kubernetes YAML — Deployment, Service, ConfigMap, Ingress, RBAC, StatefulSet, CRDs. | akin-ozer/ | 320 | — | ~2.2k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 23 | 23.Kubernetes Kubernetes operations: debugging, security, RBAC, and infrastructure tooling. | notque/ | 441 | — | ~1.5k | Automated safety check: Pass | MIT | 2 days ago |
| 24 | Secures Helm chart deployments by verifying chart signatures and provenance, rendering and linting templates for misconfiguration, enforcing pod security contexts through values.yaml, moving secrets… | mukul975/ | 34k | — | ~1.9k | Automated safety check: Warn | Apache-2.0 | 1 mo ago |
| 25 | DevSecOps, container, and API operational defensive security reference: CI/CD pipeline hardening, secret scanning, IaC misconfiguration detection, SAST/DAST integration, container image scanning… | modu-ai/ | 1.2k | — | ~2.6k | Automated safety check: Pass | Apache-2.0 | 2 days ago |
| 26 | A Senior DevOps engineer interviewer focused on Kubernetes fundamentals. | PrepLabsAI/ | 112 | — | ~3.4k | Automated safety check: Pass | MIT | 4 days ago |
| 27 | Harden and monitor a Kubernetes cluster against the attacks that actually happen — RBAC least privilege and escalation paths, Pod Security Admission enforcement, network policy default-deny, secrets… | trilwu/ | 157 | — | ~2.2k | Automated safety check: Pass | MIT | 1 mo ago |
| 28 | Review CAST AI identity, Kubernetes RBAC, cloud IAM, Kvisor, network, and evidence boundaries against enabled features. | jeremylongshore/ | 2.8k | — | ~1.2k | Automated safety check: Pass | MIT | yesterday |
| 29 | Operate kubectl, kube-bench, Trivy, Prowler, and manifest/runtime evidence for advanced Kubernetes security assessment. | cyberful/ | 135 | — | ~898 | Automated safety check: Pass | AGPL-3.0 | 1 mo ago |
| 30 | Analyze kubernetes rbac analyzer operations. An agent skill from jeremylongshore/tons-of-skills-marketplace. | jeremylongshore/ | 2.8k | — | ~590 | Automated safety check: Pass | MIT | yesterday |
| 31 | Istio Service Mesh 安全策略绕过。当目标 K8s 集群使用 Istio、请求被 AuthorizationPolicy 拒绝(403 RBAC denied)、或发现 Envoy sidecar 时使用。核心手法:UID 1337 绕过 Envoy。任何在 K8s 中遇到 Istio 策略阻拦、Service Mesh 限制、或 Envoy 相关安全控制的场景都应使用此技能 | wgpsec/ | 1.8k | — | ~727 | Automated safety check: Pass | No licence | yesterday |
| 32 | Comprehensive OWASP-aligned security guidance across six standards - Top 10 (2021) for web apps, ASVS 5.0, MASVS v2.1.0 for mobile, API Security Top 10 (2023), Kubernetes Top 10 (2022), and the… | davila7/ | 33k | — | ~7.4k | Automated safety check: Warn | MIT | yesterday |