Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
kubeeye — Cloud-natives Kubernetes-Cluster-Inspektionstool, das Anwendungsfehlkonfigurationen, fehlerhafte Komponenten und Knotenprobleme mithilfe von benutzerdefinierten OPA-, PromQL- und Systemregeln erkennt. | Kitploit
Tools/GitHubGitHub/kubesphere/kubeeye
Cloud-Infrastruktur-SicherheitContainer-SicherheitSchwachstellenanalyseKonfigurationsprüfungCloud-SicherheitFehlkonfiguration
GitHubkubesphere/kubeeye

kubeeye

Cloud-natives Kubernetes-Cluster-Inspektionstool, das Anwendungsfehlkonfigurationen, fehlerhafte Komponenten und Knotenprobleme mithilfe von benutzerdefinierten OPA-, PromQL- und Systemregeln erkennt.

Repository anzeigen
8521896vor 1 JahrVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Webseite
Teilen

English | 中文

KubeEye ist ein Cloud-natives Cluster-Inspektionstool, das speziell für Kubernetes entwickelt wurde und in der Lage ist, Probleme und Risiken im Kubernetes-Cluster basierend auf benutzerdefinierten Regeln zu identifizieren.

Schnellstart

Installation

Laden Sie das Installationspaket von Releases herunter. Es enthält Helm-Chart, Demo-Regeln und Images für die Offline-Installation.

root@kitploit:~
VERSION=v1.0.3

wget https://github.com/kubesphere/kubeeye/releases/download/${VERSION}/kubeeye-offline-${VERSION}.tar.gz

tar -zxvf kubeeye-offline-${VERSION}.tar.gz

cd kubeeye-offline-${VERSION}

# offline installation, please import the images in the 'images' folder into the local container repository yourself and modify the images repo in `chart/kubeeye/values.yaml`.

helm upgrade --install kubeeye chart/kubeeye -n kubeeye-system --create-namespace

Verwendung

Importieren von Inspektionsregeln

Das Verzeichnis rules im Installationspaket enthält Demo-Regeln, die nach Bedarf angepasst werden können.

Hinweis: Bei PromQL-Regeln muss der Endpunkt von Prometheus im Voraus festgelegt werden.

root@kitploit:~
kubectl apply -f rules

Erstellen eines Inspektionsplans

Konfigurieren Sie Inspektionspläne nach Bedarf.

root@kitploit:~
cat > plan.yaml << EOF
apiVersion: kubeeye.kubesphere.io/v1alpha2
kind: InspectPlan
metadata:
  name: inspectplan
spec:
  # The planned time for executing inspections only supports cron expressions. For example, '*/30 * * * ?' means that the inspection will be performed every 30 minutes.'
  # If only a single inspection is required, then remove this parameter.
  schedule: "* */12 * * ?"
  # The maximum number of retained inspection results, if not filled in, will retain all.
  maxTasks: 10 
  # Should the inspection plan be paused, applicable only to periodic inspections, true or false (default is false).
  suspend: false
  # Inspection timeout, default 10 minutes.
  timeout: 10m
  # Inspection rule list, used to associate corresponding inspection rules, please fill in the inspectRule name.
  # Execute `kubectl get inspectrule` to view the inspection rules in the cluster.
  ruleNames:
  - name: configmap-inspect-rules
  - name: cronjob-inspect-rules
  - name: daemonset-inspect-rules
  - name: deployment-inspect-rules
  - name: event-inspect-rules
  - name: job-inspect-rules
  - name: node-inspect-rules
  - name: pod-inspect-rules
  - name: pod-state-inspect-rules
  # nodeName: master
  # nodeSelector:
  #   node-role.kubernetes.io/master: ""        
  # Multi-cluster inspection (currently only supports multi-cluster inspection in KubeSphere)
  # clusterName: 
  # - name: host
EOF


kubectl apply -f plan.yaml

Abrufen von Inspektionsberichten

Überprüfen der Inspektionsergebnisse
root@kitploit:~
# View the name of the inspection result for inspection report download.
kubectl get inspectresult
Befehl
root@kitploit:~
## Get the address and port of kubeeye-apiserver service.
kubectl get svc -n kubeeye-system kubeeye-apiserver -o custom-columns=CLUSTER-IP:.spec.clusterIP,PORT:.spec.ports[*].port

## Download the inspection report, and please replace <> with the actual information obtained from the environment.
curl http://<svc-ip>:9090/kapis/kubeeye.kubesphere.io/v1alpha2/inspectresults/<result name>\?type\=html -o inspectReport.html

## After downloading, you can use a browser to open the HTML file for viewing.
Web-Konsole
root@kitploit:~
## Create a nodePort type svc for kubeeye-apiserver.
kubectl -n kubeeye-system expose deploy kubeeye-apiserver --port=9090 --type=NodePort --name=ke-apiserver-node-port

## Enter the inspection report URL in the browser to view, and remember to replace <> with the actual information obtained from the environment.
http://<node address>:<node port>/kapis/kubeeye.kubesphere.io/v1alpha2/inspectresults/<result name>?type=html

Liste der unterstützten Regeln

  • OPA
  • PromQL
  • Dateiänderung
  • Kernel-Parameter-Konfiguration
  • Systemd-Dienststatus
  • Knoten-Basisinformationen
  • Dateiinhalt-Inspektion
  • Dienstkonnektivität
Tool herunterladen