Converts kube-bench checks console output to CSV.
Project description
kube-bench-report-converter-2
Converts kube-bench execution console output to a CSV report.
Install
PyPI
pip3 install -U kube-bench-report-converter-2
Source
git clone git@github.com:pjaudiomv/kube-bench-report-converter-2.git
cd kube-bench-report-converter-2/
pip3 install .
Use
cat kube-bench.log | kube-bench-report-converter-2 > kube-bench-report.csv
or
kube-bench-report-converter-2 --input_file_path 'kube-bench.log' --output_file_path 'kube-bench-report.csv'
To include WARNING level findings in the report:
kube-bench-report-converter-2 --input_file_path 'kube-bench.log' --output_file_path 'kube-bench-report.csv' --include_warnings
Arguments
| Name | Description | Default |
|---|---|---|
| input_file_path | kube-bench execution console output. | Read from stdin. |
| output_file_path | kube-bench CSV report file path. | Write to stdout. |
| include_warnings | Include WARNING level findings in the report. | False |
Running Tests
To run tests, you'll need to install the test dependencies:
pip3 install pytest pytest-cov
Then run the tests with pytest:
python3 -m pytest -v
For coverage reporting:
python3 -m pytest -v --cov=kube_bench_report_converter_2 --cov-report=term --cov-report=html
Example
Input
[INFO] 3 Worker Node Security Configuration
[INFO] 3.1 Worker Node Configuration Files
[PASS] 3.1.1 Ensure that the kubeconfig file permissions are set to 644 or more restrictive (Manual)
[PASS] 3.1.2 Ensure that the kubelet kubeconfig file ownership is set to root:root (Manual)
[PASS] 3.1.3 Ensure that the kubelet configuration file has permissions set to 644 or more restrictive (Manual)
[PASS] 3.1.4 Ensure that the kubelet configuration file ownership is set to root:root (Manual)
[INFO] 3.2 Kubelet
[PASS] 3.2.1 Ensure that the --anonymous-auth argument is set to false (Automated)
[PASS] 3.2.2 Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
[PASS] 3.2.3 Ensure that the --client-ca-file argument is set as appropriate (Manual)
[PASS] 3.2.4 Ensure that the --read-only-port argument is set to 0 (Manual)
[PASS] 3.2.5 Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Manual)
[PASS] 3.2.6 Ensure that the --protect-kernel-defaults argument is set to true (Automated)
[PASS] 3.2.7 Ensure that the --make-iptables-util-chains argument is set to true (Automated)
[PASS] 3.2.8 Ensure that the --hostname-override argument is not set (Manual)
[PASS] 3.2.9 Ensure that the --eventRecordQPS argument is set to 0 or a level which ensures appropriate event capture (Automated)
[PASS] 3.2.10 Ensure that the --rotate-certificates argument is not set to false (Manual)
[PASS] 3.2.11 Ensure that the RotateKubeletServerCertificate argument is set to true (Manual)
[INFO] 3.3 Container Optimized OS
[WARN] 3.3.1 Prefer using Container-Optimized OS when possible (Manual)
== Remediations node ==
3.3.1 audit test did not run: No tests defined
== Summary node ==
15 checks PASS
0 checks FAIL
1 checks WARN
0 checks INFO
== Summary total ==
15 checks PASS
0 checks FAIL
1 checks WARN
0 checks INFO
Output (without warnings)
Id,Category,Subcategory,Rating,Description,Remediation
"3.1.1","Worker Node Security Configuration","Worker Node Configuration Files","PASS","Ensure that the kubeconfig file permissions are set to 644 or more restrictive (Manual)",""
"3.1.2","Worker Node Security Configuration","Worker Node Configuration Files","PASS","Ensure that the kubelet kubeconfig file ownership is set to root:root (Manual)",""
"3.1.3","Worker Node Security Configuration","Worker Node Configuration Files","PASS","Ensure that the kubelet configuration file has permissions set to 644 or more restrictive (Manual)",""
"3.1.4","Worker Node Security Configuration","Worker Node Configuration Files","PASS","Ensure that the kubelet configuration file ownership is set to root:root (Manual)",""
"3.2.1","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --anonymous-auth argument is set to false (Automated)",""
"3.2.2","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)",""
"3.2.3","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --client-ca-file argument is set as appropriate (Manual)",""
"3.2.4","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --read-only-port argument is set to 0 (Manual)",""
"3.2.5","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Manual)",""
"3.2.6","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --protect-kernel-defaults argument is set to true (Automated)",""
"3.2.7","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --make-iptables-util-chains argument is set to true (Automated)",""
"3.2.8","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --hostname-override argument is not set (Manual)",""
"3.2.9","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --eventRecordQPS argument is set to 0 or a level which ensures appropriate event capture (Automated)",""
"3.2.10","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --rotate-certificates argument is not set to false (Manual)",""
"3.2.11","Worker Node Security Configuration","Kubelet","PASS","Ensure that the RotateKubeletServerCertificate argument is set to true (Manual)",""
Output (with warnings)
Id,Category,Subcategory,Rating,Description,Remediation
"3.1.1","Worker Node Security Configuration","Worker Node Configuration Files","PASS","Ensure that the kubeconfig file permissions are set to 644 or more restrictive (Manual)",""
"3.1.2","Worker Node Security Configuration","Worker Node Configuration Files","PASS","Ensure that the kubelet kubeconfig file ownership is set to root:root (Manual)",""
"3.1.3","Worker Node Security Configuration","Worker Node Configuration Files","PASS","Ensure that the kubelet configuration file has permissions set to 644 or more restrictive (Manual)",""
"3.1.4","Worker Node Security Configuration","Worker Node Configuration Files","PASS","Ensure that the kubelet configuration file ownership is set to root:root (Manual)",""
"3.2.1","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --anonymous-auth argument is set to false (Automated)",""
"3.2.2","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)",""
"3.2.3","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --client-ca-file argument is set as appropriate (Manual)",""
"3.2.4","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --read-only-port argument is set to 0 (Manual)",""
"3.2.5","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Manual)",""
"3.2.6","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --protect-kernel-defaults argument is set to true (Automated)",""
"3.2.7","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --make-iptables-util-chains argument is set to true (Automated)",""
"3.2.8","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --hostname-override argument is not set (Manual)",""
"3.2.9","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --eventRecordQPS argument is set to 0 or a level which ensures appropriate event capture (Automated)",""
"3.2.10","Worker Node Security Configuration","Kubelet","PASS","Ensure that the --rotate-certificates argument is not set to false (Manual)",""
"3.2.11","Worker Node Security Configuration","Kubelet","PASS","Ensure that the RotateKubeletServerCertificate argument is set to true (Manual)",""
"3.3.1","Worker Node Security Configuration","Container Optimized OS","WARN","Prefer using Container-Optimized OS when possible (Manual)","audit test did not run: No tests defined"
Attribution
This project is based on or originally forked from kube-bench-report-converter by Michael Lewkowski.
Many thanks to the original author for the foundation of this work.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file kube_bench_report_converter_2-0.0.2.tar.gz.
File metadata
- Download URL: kube_bench_report_converter_2-0.0.2.tar.gz
- Upload date:
- Size: 6.3 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.12.9
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b8286ebe2a7bbf4e0aeac76ae099108ab6aa424f964a56877b15655e717ec856
|
|
| MD5 |
627d9babfe34f61c1a1fe25e211ac74a
|
|
| BLAKE2b-256 |
435755d544cc9ebeab91acc7fec55bcd5b5049ea536c2feeecada71965973c53
|
File details
Details for the file kube_bench_report_converter_2-0.0.2-py3-none-any.whl.
File metadata
- Download URL: kube_bench_report_converter_2-0.0.2-py3-none-any.whl
- Upload date:
- Size: 7.1 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.12.9
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
9813128d3f1b0399ddf9fa6bb76fe09505d6cfff61154e92d39e6e6b02869cfa
|
|
| MD5 |
49756465facfa48f824a8cd5c777ae22
|
|
| BLAKE2b-256 |
8cd96589bdd07ef5072771654de80a045e44e948cbee3251b3c5f0583017337a
|