docs: add Kubernetes CKS study notes

This commit is contained in:
2026-08-04 23:18:45 +02:00
parent a6ee7a2b07
commit 91a1849009
57 changed files with 8313 additions and 0 deletions

View File

@@ -0,0 +1,33 @@
#!/usr/bin/env bash
# CKS mock — cluster bootstrap. Run on your Ubuntu VM (needs docker, kind >= v0.32.0, kubectl v1.35, helm).
set -euo pipefail
HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
cd "$HERE"
mkdir -p exam-files
echo "[*] Creating kind cluster 'cks' (1 cp + 2 workers, k8s v1.35.5)..."
kind create cluster --config kind-config.yaml
kubectl config use-context kind-cks
echo "[*] Installing an ingress controller (needed for the TLS task)..."
kubectl apply -f https://raw.githubusercontent.com/kubernetes/ingress-nginx/main/deploy/static/provider/kind/deploy.yaml
kubectl -n ingress-nginx wait --for=condition=Ready pod \
-l app.kubernetes.io/component=controller --timeout=180s || true
cat <<'EOF'
[*] Cluster up. Sanity check:
kubectl get nodes -o wide
[*] Host-side tooling you want on the VM (install latest):
- kube-bench : https://github.com/aquasecurity/kube-bench/releases (or run as a Job in-cluster)
- trivy : https://github.com/aquasecurity/trivy (apt: aquasecurity repo)
- kubesec : https://github.com/controlplaneio/kubesec/releases
- falco : apt install falco (v0.44.1) — used in the runtime task on the VM
- helm : for Kyverno / Falco chart installs
- cosign : optional, image signing task
[*] Now run ./seed.sh to plant the vulnerable/target objects for the kubectl-only tasks.
EOF