OSS Tanbou

audit Kubernetes node and cluster configuration against CIS Benchmark checks

About these scores

OSS scale score is an unbounded metric that log-compresses and weights Stars, Watchers, Forks, and Contributors. Discovery score is the current OSS scale score minus the score at discovery. Update pace is commits in the last 30 days, growth momentum is the OSS scale score difference within the recent observation window, and OSS health is a 0–100 rating based on available recency, Community Health, and release data.

Stars
8,209
Primary language
Go
License
Apache-2.0
Repository last updated
Oct 1, 2026
On this page

Overview

kube-bench is a security checking tool that compares Kubernetes configuration with CIS Kubernetes Benchmark and related hardening guidance. It inspects process arguments, configuration files, permissions, API server settings, and other controls, then reports PASS, FAIL, and WARN results.

Features and best fit

Based on official documentation; not hands-on tested · Content checked:

Key features

Automate CIS Kubernetes Benchmark checks

Checks are defined in YAML around CIS Benchmark controls and inspect Kubernetes component flags, file permissions, configuration values, and related settings. This turns repeatable parts of manual hardening review into a CLI workflow.

Sources: [1][3]

Run as a cluster Job or as a binary on a node

The supplied Job manifest can run kube-bench inside Kubernetes, while binaries or containers can also run directly on a node. In-cluster execution requires access to host PID and configuration paths needed by the checks.

Sources: [1][4]

Select benchmark configuration from the Kubernetes version

By default kube-bench detects the Kubernetes version and selects a matching benchmark configuration. Operators can also explicitly choose benchmark or platform-specific profiles when needed.

Sources: [1][3]

Best fit

Fits periodic Kubernetes hardening audits and before/after comparisons

It is useful for baseline checks during cluster build, post-upgrade audits, security reviews, and repeated configuration-drift detection. Keeping results over time helps track hardening changes.

Sources: [1][4]

Before adoption

v0.16.0 is the current stable release

v0.16.0, published August 5, 2026, is the current stable release. Benchmark definitions do not update on the same cadence as Kubernetes, so verify both the tool version and supported benchmark matrix.

Sources: [2][3]

CIS Benchmark and Kubernetes versions are not one-to-one

For example, the support matrix maps CIS 1.12 to Kubernetes 1.32-1.33 and CIS 2.0 to Kubernetes 1.34-1.35. Record the actual cluster version and the benchmark profile selected for each audit.

Sources: [3]

Some checks cannot be remediated directly on managed Kubernetes

On EKS, GKE, AKS, and other managed platforms, some control-plane settings are owned by the cloud provider. Do not translate every FAIL or WARN into a node change; use platform-specific benchmarks and responsibility boundaries.

Sources: [3][4]

Official sources

  1. [1]kube-bench README(2026-10-03)
  2. [2]kube-bench v0.16.0 release(2026-10-03)
  3. [3]kube-bench supported platforms(2026-10-03)
  4. [4]Running kube-bench(2026-10-03)
Supplemental curator note

A kube-bench FAIL indicates a difference from the CIS Benchmark expectation, not automatically an exploitable vulnerability. On managed Kubernetes, some control-plane settings are outside the user's responsibility, so record platform ownership and justified exceptions alongside the scan result.

Try it in 3 steps

  1. 1

    Clone the kube-bench v0.16.0 source

    Pin the release tag so the official job.yaml is tied to the tested version.

    git clone --depth 1 --branch v0.16.0 https://github.com/aquasecurity/kube-bench.git && cd kube-bench
  2. 2

    Run it as a Kubernetes Job

    The Job accesses host PID and configuration paths required by CIS checks. Confirm that this access is acceptable in the target cluster.

    kubectl apply -f job.yaml
  3. 3

    Read the audit result from Job logs

    After the Job completes, inspect PASS, FAIL, and WARN results. On managed Kubernetes, review provider responsibility before treating every FAIL as a directly remediable setting.

    kubectl logs job/kube-bench
Check the official README

Growth

Growth trends · Last 30 days

8,209 Stars

Trend data is still being collected.

Development activity

Last 90 days · weekly

Commits (last 30 days)
3
Open PRs
37

Development activity is still being collected.

Built with

Categories and tags

GitHub data

GitHub dataView detailed GitHub data

GitHub Topics

  • kube-bench
  • cis-security
  • kubernetes-security
  • cis-benchmark
  • cis-kubernetes-benchmark
  • openshift
  • kubernetes
  • hacktoberfest
Stars
8,209
Forks
1,341
Watchers
107
Open issues
70
Contributors
165
Owner type
Organization
Primary language
Go
License
Apache-2.0
Repository last updated
Oct 1, 2026
Write a related article

Share a guide or use case for this OSS in Markdown. Articles are published after administrator approval.

Report incorrect information

Tell us if any listing information is incorrect or outdated.

After reading this page, do you know what to do next?