Comment 4 for bug 2044219

Revision history for this message
Kevin W Monroe (kwmonroe) wrote :

CIS Kubernetes Benchmark scanning was made available in the Trivy CLI (in addition to quite a few more trivy features) last year:

https://www.aquasec.com/blog/trivy-kubernetes-cis-benchmark-scanning/

I've confirmed the manual steps from comment #2 are still valid for charmed k8s 1.29, as are the upstream trivy getting started instructions. Given that, the better solution here is to include something like a `trivy` action as a superset of the functionality that the `cis-benchmark` action provided.

I'm re-targeting this for the upcoming 1.30 release.