- awesome-docker tool list on github
- https://github.com/veggiemonk/awesome-docker/blob/master/README.md#terminal
- Open Policy Agent (OPA): cluster policies :
** https://github.com/open-policy-agent/opa
- KubeLinter: yaml linter :
** https://www.redhat.com/en/topics/containers/what-is-kubelinter
- Kube-bench - configuration scanner
** https://github.com/aquasecurity/kube-bench
- Kube-hunter - Testing tool & pentesting
** https://github.com/aquasecurity/kube-hunter
- Terrascan - static code analyzer - compliance & security for terraform/yaml,kustomize,docker
** https://github.com/accurics/terrascan
- Falco - pod or node or both
- Clair - container static analyzer
** https://github.com/quay/clair
- Checkov - scan IaC
** https://www.checkov.io/ ** https://docs.bridgecrew.io/docs/kubernetes-policy-index ** https://www.checkov.io/7.Scan%20Examples/Argo%20Workflows.html
- Sandfly security - node security
** https://www.sandflysecurity.com/get-sandfly/
- Trivvy - container scanning
** https://github.com/aquasecurity/trivy
- snyk io
** https://snyk.io/ ** https://support.snyk.io/hc/en-us/articles/360003946917-Test-images-with-the-Snyk-Container-CLI
- anchore
** https://docs.anchore.com/current/
- aquasec
- kubei
** https://github.com/Portshift/kubei
- Palo Alto twsitcli
** Scan images with twistcli - Palo Alto Networkshttps://docs.paloaltonetworks.com › prisma-cloud › tools
- sysdig
** https://sysdig.com/products/secure/
- kubesec
** https://github.com/controlplaneio/kubesec/releases
- kubehunter - aquasec
** https://github.com/aquasecurity/kube-hunter
-
kdave
-
kube-bench - aquasec
** https://github.com/aquasecurity/kube-bench
-
kubeaudit
-
Trivy Operator/CRD - vuln scan, audit and reporting to prom or other, argo integration
** https://github.com/aquasecurity/trivy-operator
ref link:https://www.openanalytics.eu/blog/2021/02/23/kustomize-best-practices/
- gpg: user multi file
- SOPS: https://github.com/mozilla/sops
- vault hashicorp: https://github.com/benmorehouse/kustomize-vault
- admiralty
- shipper
- kubfed
- Rancher
- Rancher
- Fleet
- Fleet is a GitOps-at-scale project designed to facilitate and manage a multi-cluster environment.
- Google Anthos
- Google Anthos is designed to extend the Google Kubernetes engine across hybrid and multi-cluster environments.
- Das shift engine
- https://rafay.co/ - governance and automation
- https://www.paralus.io/ - policy management - access mgt, sso, rbac, auditing, zerotrust just in time accouting
- https://blog.kubernauts.io/deploy-k8s-using-k8s-with-cluster-api-and-capa-on-aws-107669808367
- CAPI
- CAPA
https://github.com/projectatomic/dockerfile_lint
- stern/stern formerly known as wercker/stern