On this page
Overview
kube-bench is a security checking tool that compares Kubernetes configuration with CIS Kubernetes Benchmark and related hardening guidance. It inspects process arguments, configuration files, permissions, API server settings, and other controls, then reports PASS, FAIL, and WARN results.
Features and best fit
Based on official documentation; not hands-on tested · Content checked:
Key features
Automate CIS Kubernetes Benchmark checks
Checks are defined in YAML around CIS Benchmark controls and inspect Kubernetes component flags, file permissions, configuration values, and related settings. This turns repeatable parts of manual hardening review into a CLI workflow.
Run as a cluster Job or as a binary on a node
The supplied Job manifest can run kube-bench inside Kubernetes, while binaries or containers can also run directly on a node. In-cluster execution requires access to host PID and configuration paths needed by the checks.
Best fit
Before adoption
v0.16.0 is the current stable release
v0.16.0, published August 5, 2026, is the current stable release. Benchmark definitions do not update on the same cadence as Kubernetes, so verify both the tool version and supported benchmark matrix.
CIS Benchmark and Kubernetes versions are not one-to-one
For example, the support matrix maps CIS 1.12 to Kubernetes 1.32-1.33 and CIS 2.0 to Kubernetes 1.34-1.35. Record the actual cluster version and the benchmark profile selected for each audit.
Sources: [3]
Some checks cannot be remediated directly on managed Kubernetes
On EKS, GKE, AKS, and other managed platforms, some control-plane settings are owned by the cloud provider. Do not translate every FAIL or WARN into a node change; use platform-specific benchmarks and responsibility boundaries.
Official sources
- [1]kube-bench README(2026-10-03)
- [2]kube-bench v0.16.0 release(2026-10-03)
- [3]kube-bench supported platforms(2026-10-03)
- [4]Running kube-bench(2026-10-03)
Supplemental curator note
A kube-bench FAIL indicates a difference from the CIS Benchmark expectation, not automatically an exploitable vulnerability. On managed Kubernetes, some control-plane settings are outside the user's responsibility, so record platform ownership and justified exceptions alongside the scan result.
Try it in 3 steps
- 1
Clone the kube-bench v0.16.0 source
Pin the release tag so the official
job.yamlis tied to the tested version.git clone --depth 1 --branch v0.16.0 https://github.com/aquasecurity/kube-bench.git && cd kube-bench - 2
Run it as a Kubernetes Job
The Job accesses host PID and configuration paths required by CIS checks. Confirm that this access is acceptable in the target cluster.
kubectl apply -f job.yaml - 3
Read the audit result from Job logs
After the Job completes, inspect PASS, FAIL, and WARN results. On managed Kubernetes, review provider responsibility before treating every FAIL as a directly remediable setting.
kubectl logs job/kube-bench
Growth
Growth trends · Last 30 days
8,209 Stars
Trend data is still being collected.
Development activity
Last 90 days · weekly
- Commits (last 30 days)
- 3
- Open PRs
- 37
Development activity is still being collected.
Built with
Categories and tags
GitHub data
GitHub dataView detailed GitHub data
GitHub Topics
- kube-bench
- cis-security
- kubernetes-security
- cis-benchmark
- cis-kubernetes-benchmark
- openshift
- kubernetes
- hacktoberfest
- Stars
- 8,209
- Forks
- 1,341
- Watchers
- 107
- Open issues
- 70
- Contributors
- 165
- Owner type
- Organization
- Primary language
- Go
- License
- Apache-2.0
- Repository last updated
- Oct 1, 2026
Related information
Write a related articleShare a guide or use case for this OSS in Markdown. Articles are published after administrator approval.
Explore next
- minikube32,168 Stars
3 shared tag(s) · 2 shared category(s) · Same language
create a workstation Kubernetes cluster for pre-deployment testing
Go - Helm30,299 Stars
3 shared tag(s) · 2 shared category(s) · Same language
package Kubernetes applications as Charts and manage install, upgrade, and rollback as releases
Go - containerd21,377 Stars
3 shared tag(s) · 2 shared category(s) · Same language
embed an industry-standard runtime daemon for image transfer, snapshots, container execution, and supervision beneath Kubernetes and container platforms
Go - Kyverno8,212 Stars
3 shared tag(s) · 2 shared category(s) · Same language
Continuously apply policy as code through Kubernetes admission and background scans
Go - Checkov9,054 Stars
3 shared tag(s) · 2 shared category(s)
statically analyze Terraform, Kubernetes, and other infrastructure as code to catch cloud misconfigurations, policy violations, and dependency risks before deployment
Python - Istio38,428 Stars
3 shared tag(s) · 1 shared category(s) · Same language
add mTLS, traffic policy, and telemetry transparently between services
Go
Report incorrect information
Tell us if any listing information is incorrect or outdated.