Control: GKE clusters binary authorization should be enabled
Description
This control ensures that GKE clusters binary authorization is enabled.
Usage
Run the control in your terminal:
powerpipe control run gcp_compliance.control.kubernetes_cluster_binary_authorization_enabled
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run gcp_compliance.control.kubernetes_cluster_binary_authorization_enabled --share
SQL
This control uses a named query:
select self_link resource, case when binary_authorization is null or (binary_authorization ->> 'evaluationMode') ilike 'DISABLED' or (binary_authorization ->> 'evaluationMode') ilike 'EVALUATION_MODE_UNSPECIFIED' then 'alarm' else 'ok' end as status, case when binary_authorization is null or (binary_authorization ->> 'evaluationMode') ilike 'DISABLED' or (binary_authorization ->> 'evaluationMode') ilike 'EVALUATION_MODE_UNSPECIFIED' then title || ' binary authorization disabled.' else title || ' binary authorization enabled.' end as reason , location as location, project as projectfrom gcp_kubernetes_cluster;