Registry
SKILL

gke-workload-security

outshift.io Unverified — relayed by outshift.io . Discovered through outshift.io's registry, not anchored by StealthStack. We relay the listing as-is; we have not checked that the URN authority matches the publishing host. seen 1h ago

About

Audits, configures, and hardens workload-level security controls for Google Kubernetes Engine (GKE) applications and namespaces. Covers running cluster security audits (`audit_cluster.sh`), configuring Workload Identity Federation (impersonation, KSA/GSA binding, and pod setup), enforcing Network Policies (default-deny and Dataplane V2 logging), isolating high-risk pods inside GKE Sandbox (`gVisor`), enforcing Pod Security Standards (`restricted` labeling), and mounting Secret Manager secrets via CSI (`SecretProviderClass`). Use when auditing cluster security posture, isolating namespaces, applying pod security standards, setting up Workload Identity, or configuring network policies and secret volume mounts. Don't use for cluster-wide control plane security, RBAC hardening, Binary Authorization, Shielded Nodes, or enabling platform-level GKE add-ons (use gke-platform-security instead).

Capabilities

The crawler did not record capability metadata for this resource. Inspect the endpoint directly to see what it exposes.

Provenance

Discovered
Relayed by agntcy
Identifier
urn:air:outshift.io:agntcy:gke-workload-security
Catalog host
outshift.io · via agntcy registry
Anchor check
Not anchored
Last crawled
seen 1h ago

Discovered through outshift.io's registry, not anchored by StealthStack. We relay the listing as-is; we have not checked that the URN authority matches the publishing host. How trust works →

Tags