diff --git a/README.md b/README.md index 14c0713c..c0816d0a 100644 --- a/README.md +++ b/README.md @@ -4,7 +4,13 @@ [![Gitpod Ready-to-Code](https://img.shields.io/badge/Gitpod-Ready--to--Code-blue?logo=gitpod)](https://gitpod.io/#https://github.com/kubescape/kubescape) [![GitHub](https://img.shields.io/github/license/kubescape/kubescape)](https://github.com/kubescape/kubescape/blob/master/LICENSE) [![CNCF](https://shields.io/badge/CNCF-Sandbox%20project-blue?logo=linux-foundation&style=flat)](https://landscape.cncf.io/card-mode?project=sandbox&selected=kubescape) +[![Artifact HUB](https://img.shields.io/endpoint?url=https://artifacthub.io/badge/repository/kubescape)](https://artifacthub.io/packages/search?repo=kubescape) +[![FOSSA Status](https://app.fossa.com/api/projects/git%2Bgithub.com%2Fkubescape%2Fkubescape.svg?type=shield&issueType=license)](https://app.fossa.com/projects/git%2Bgithub.com%2Fkubescape%2Fkubescape?ref=badge_shield&issueType=license) +[![OpenSSF Best Practices](https://www.bestpractices.dev/projects/6944/badge)](https://www.bestpractices.dev/projects/6944) +[![OpenSSF Scorecard](https://api.securityscorecards.dev/projects/github.com/kubescape/kubescape/badge)](https://securityscorecards.dev/viewer/?uri=github.com/kubescape/kubescape) +[![Stars](https://img.shields.io/github/stars/kubescape/kubescape?style=social)](https://github.com/kubescape/kubescape/stargazers) [![Twitter Follow](https://img.shields.io/twitter/follow/kubescape?style=social)](https://twitter.com/kubescape) +[![Slack](https://img.shields.io/badge/slack-kubescape-blueviolet?logo=slack)](https://cloud-native.slack.com/archives/C04EY3ZF9GE) # Kubescape @@ -22,11 +28,14 @@ Kubescape scans clusters, YAML files, and Helm charts. It detects misconfigurati Kubescape was created by [ARMO](https://www.armosec.io/?utm_source=github&utm_medium=repository) and is a [Cloud Native Computing Foundation (CNCF) sandbox project](https://www.cncf.io/sandbox-projects/). -## Demo - - _Please [star ⭐](https://github.com/kubescape/kubescape/stargazers) the repo if you want us to continue developing and improving Kubescape! 😀_ +## Demo + +Kubescape has a command line tool that you can use to quickly get a report on the security posture of a Kubernetes cluster: + + + ## Getting started Experimenting with Kubescape is as easy as: @@ -35,13 +44,13 @@ Experimenting with Kubescape is as easy as: curl -s https://raw.githubusercontent.com/kubescape/kubescape/master/install.sh | /bin/bash ``` +This script will automatically download the latest Kubescape CLI release and scan the Kubernetes cluster in your current kubectl context. + Learn more about: -* [Installing Kubescape](docs/installation.md) -* [Running your first scan](docs/getting-started.md#run-your-first-scan) -* [Usage](docs/getting-started.md#examples) -* [Architecture](docs/architecture.md) -* [Building Kubescape from source](https://github.com/kubescape/kubescape/wiki/Building) +* [Installing the Kubescape CLI](https://kubescape.io/docs/install-cli/) +* [Running your first scan](https://kubescape.io/docs/scanning/) +* [Accepting risk with exceptions](https://kubescape.io/docs/accepting-risk/) _Did you know you can use Kubescape in all these places?_ @@ -49,6 +58,14 @@ _Did you know you can use Kubescape in all these places?_ Places you can use Kubescape: in your IDE, CI, CD, or against a running cluster. +### Continuous security monitoring with the Kubescape Operator + +As well as a CLI, Kubescape provides an in-cluster mode, which is installed via a Helm chart. Kubescape in-cluster provides extensive features such as continuous scanning, image vulnerability scanning, runtime analysis, network policy generation, and more. [Learn more about the Kubescape operator](https://kubescape.io/docs/operator/). + +### Using Kubescape as a GitHub Action + +Kubescape can be used as a GitHub Action. This is a great way to integrate Kubescape into your CI/CD pipeline. You can find the Kubescape GitHub Action in the [GitHub Action marketplace](https://github.com/marketplace/actions/kubescape). + ## Under the hood Kubescape uses [Open Policy Agent](https://github.com/open-policy-agent/opa) to verify Kubernetes objects against [a library of posture controls](https://github.com/kubescape/regolibrary). @@ -56,13 +73,15 @@ For image scanning, it uses [Grype](https://github.com/anchore/grype). For image patching, it uses [Copacetic](https://github.com/project-copacetic/copacetic). For eBPF, it uses [Inspektor Gadget](https://github.com/inspektor-gadget) -By default, the results are printed in a console-friendly manner, but they can be: +By default, CLI scan results are printed in a console-friendly manner, but they can be: -* exported to JSON or junit XML +* exported to JSON, junit XML or SARIF * rendered to HTML or PDF * submitted to a [cloud service](docs/providers.md) -It retrieves Kubernetes objects from the API server and runs a set of [Rego snippets](https://www.openpolicyagent.org/docs/latest/policy-language/) developed by [ARMO](https://www.armosec.io?utm_source=github&utm_medium=repository). +### In-cluster architecture + +![Architecture diagram](docs/img/architecture-diagram.png) ## Community @@ -86,8 +105,13 @@ We would like to take this opportunity to thank all our contibutors to date. +## Changelog + +Kubescape changes are tracked on the [release](https://github.com/kubescape/kubescape/releases) page. + ## License +Copyright 2021-2024, the Kubescape Authors. All rights reserved. Kubescape is released under the Apache 2.0 license. See the [LICENSE](LICENSE) file for details. Copyright 2021-2024, the Kubescape Authors. All rights reserved. Kubescape is released under the Apache 2.0 license. See the [LICENSE](LICENSE) file for details. Kubescape is a [Cloud Native Computing Foundation (CNCF) sandbox project](https://www.cncf.io/sandbox-projects/) and was contributed by [ARMO](https://www.armosec.io/?utm_source=github&utm_medium=repository).