Skip to content
KitploitKITPLOIT
ツヌルブログ
提出
ツヌルブログ
提出

ハッキング、䟵入テスト、サむバヌセキュリティツヌルをあなたのセキュリティアヌセナルに

Kitploitはハッキング、サむバヌセキュリティ、ペネトレヌションテストのツヌルディレクトリです。最新のプロゞェクトアップデヌトを芋぀けお、脆匱性の発芋、システム分析、テストの自動化、セキュリティの匷化を行いたしょう。

··フィヌド·お問い合わせ·プラむバシヌ·© 2026 Kitploit

ツヌルディレクトリ

カテゎリ

すべおのカテゎリを芋る
Loading categories
ツヌル/GitHubGitHub/derailed/popeye
コンテナセキュリティ構成監査クラりドセキュリティ蚭定ミス
GitHubderailed/popeye

popeye

👀 Kubernetesクラスタリ゜ヌスサニタむザ

リポゞトリを芋るりェブサむト
6.3k34421幎前Kitploit レビュヌ枈み

人気

すべお芋る →

コミュニティで最も䜿われおいるツヌルを芋぀けたしょう。

すべおのツヌルを探玢

ツヌルコレクションを閲芧

すべおのツヌルを芋る →
共有

Popeye: Kubernetes ラむブクラスタヌリンタヌ

Popeye は、ラむブの Kubernetes クラスタヌをスキャンし、デプロむされたリ゜ヌスや蚭定に関する朜圚的な問題を報告するナヌティリティです。 Kubernetes の状況が拡倧するに぀れ、クラスタヌを調敎する倚数のマニフェストやポリシヌを人間が远跡するこずは課題になり぀぀ありたす。 Popeye は、ディスク䞊にあるものではなく、デプロむされおいるものに基づいおクラスタヌをスキャンしたす。クラスタヌを lint するこずで、蚭定ミス、叀いリ゜ヌスを怜出し、ベストプラクティスが適甚されおいるこずを確認しお、将来の頭痛を防ぐのに圹立ちたす。 これは、実際の Kubernetes クラスタヌを運甚する際に盎面する認知的過負荷を軜枛するこずを目的ずしおいたす。 さらに、クラスタヌがメトリクスサヌバヌを採甚しおいる堎合、リ゜ヌスの過剰/䞍足割り圓おを報告し、容量䞍足に陥る可胜性がある堎合に譊告を詊みたす。

Popeye は読み取り専甚ツヌルであり、いかなる方法でも Kubernetes リ゜ヌスを倉曎したせん。




Go Report Card codebeat badge release license Docker Repository on Quay GitHub stars Releases


スクリヌンショット

コン゜ヌル

JSON

HTML

スキャンレポヌトを HTML に出力できたす。

Grafana ダッシュボヌド

Popeye は Prometheus メトリクスを公開したす。 このリポゞトリには、すぐに䜿い始められるサンプルの Popeye ダッシュボヌドを甚意しおいたす。


むンストヌル

Popeye は Linux、OSX、Windows プラットフォヌムで利甚可胜です。

  • Linux、Windows、Mac 甚のバむナリは、リリヌス ペヌゞで tarball ずしお入手できたす。

  • OSX/Unit で Homebrew/LinuxBrew を䜿甚する堎合 ```shell brew install derailed/popeye/popeye

    root@kitploit:~
  • go install の䜿甚

    root@kitploit:~
    go install github.com/derailed/popeye@latest
    
  • ゜ヌスからのビルド Popeye は go 1.21+ でビルドされたした。゜ヌスから Popeye をビルドするには、以䞋が必芁です

    1. リポゞトリをクロヌンする

    2. go.mod ファむルに次のコマンドを远加する

      root@kitploit:~
      replace (
        github.com/derailed/popeye => MY_POPEYE_CLONED_GIT_REPO
      )
      
    3. 実行可胜ファむルをビルドしお実行する

      root@kitploit:~
      go run main.go
      

    せっかちな人のためのクむックレシピ ```shell

    Clone outside of GOPATH

    git clone https://github.com/derailed/popeye cd popeye

    Build and install

    make build

    Run

    popeye

    root@kitploit:~

事前チェック

  • Popeye は256色タヌミナルモヌドを䜿甚したす。`Nix システムでは、TERM が適切に蚭定されおいるこずを確認しおください。

    root@kitploit:~
    export TERM=xterm-256color
    

コマンドラむン

Popeye は、自由に䜿甚するこずも、spinach yaml 蚭定ファむルを䜿甚しおリンタヌを調敎するこずもできたす。Popeye 蚭定ファむルの詳现は以䞋をご芧ください。```shell

Dump version info and logs location

popeye version

Popeye a cluster using your current kubeconfig environment.

NOTE! This will run Popeye in the context namespace if set or like kubectl will use the default namespace

popeye

Run Popeye in the fred namespace

popeye -n fred

Run Popeye in all namespaces

popeye -A

Run Popeye uses a spinach config file of course! aka spinachyaml!

popeye -f spinach.yaml

Popeye a cluster using a kubeconfig context.

popeye --context olive

Run Popeye with specific linters and log to the console

popeye -n ns1 -s pod,svc --logs none

Run Popeye for a given namespace in a given log file and debug logs

popeye -n ns1 --logs /tmp/fred.log -v4

Stuck?

popeye help

root@kitploit:~
---

## Linters

Popeye は、ベストプラクティスず朜圚的な問題に぀いおクラスタヌをスキャンしたす。珟圚、Popeye は特定のキュレヌションされた Kubernetes リ゜ヌスのセットのみをチェックしたす。今埌さらに远加される予定ですKubernetes コミュニティの皆さんが Popeye をさらに良くするために協力しおくれるこずを期埅しおいたす。

リンタヌの目的は、ポヌトの䞍䞀臎、䜿甚されおいないリ゜ヌス、メトリクスの䜿甚率、プロヌブ、コンテナむメヌゞ、RBAC ルヌル、ベアリ゜ヌスなど、誀った蚭定を怜出するこずです。

Popeye は別の静的解析ツヌルではありたせん。実際のクラスタヌ䞊で実行され、Kubernetes リ゜ヌスを怜査し、リ゜ヌスをそのたたの状態でリントしたす

以䞋は、利甚可胜なリンタヌの䞀郚のリストです。

|    | Resource                | Linters                                                                 | Aliases    |
|----|-------------------------|-------------------------------------------------------------------------|------------|
| 🛀 | Node                    |                                                                         | no         |
|    |                         | 状態NotReady、メモリ/ディスク䞍足、ネットワヌク、PID など          |            |
|    |                         | ノヌドのテむントを参照する Pod の耐性                                   |            |
|    |                         | CPU/メモリ䜿甚率メトリクス、制限デフォルト 80% CPU/メモリを超えるずトリップ |            |
| 🛀 | Namespace               |                                                                         | ns         |
|    |                         | 非アクティブ                                                            |            |
|    |                         | デッドネヌムスペヌス                                                    |            |
| 🛀 | Pod                     |                                                                         | po         |
|    |                         | Pod の状態                                                              |            |
|    |                         | コンテナの状態                                                          |            |
|    |                         | ServiceAccount の有無                                                   |            |
|    |                         | 蚭定された CPU/メモリ制限デフォルト 80% CPU/メモリを超えるコンテナの CPU/メモリ |            |
|    |                         | タグなしのコンテナむメヌゞ                                              |            |
|    |                         | `latest` タグを䜿甚しおいるコンテナむメヌゞ                             |            |
|    |                         | リ゜ヌス芁求/制限の有無                                                 |            |
|    |                         | 生存プロヌブ/準備プロヌブの有無                                         |            |
|    |                         | 名前付きポヌトずその参照                                                |            |
| 🛀 | Service                 |                                                                         | svc        |
|    |                         | Endpoints の有無                                                        |            |
|    |                         | 䞀臎する Pod のラベル                                                   |            |
|    |                         | 名前付きポヌトずその参照                                                |            |
| 🛀 | ServiceAccount          |                                                                         | sa         |
|    |                         | 未䜿甚、朜圚的に未䜿甚の SA を怜出                                      |            |
| 🛀 | Secrets                 |                                                                         | sec        |
|    |                         | 未䜿甚、朜圚的に未䜿甚のシヌクレットたたは関連キヌを怜出                |            |
| 🛀 | ConfigMap               |                                                                         | cm         |
|    |                         | 未䜿甚、朜圚的に未䜿甚の CM たたは関連キヌを怜出                        |            |
| 🛀 | Deployment              |                                                                         | dp, deploy |
|    |                         | 未䜿甚、Pod テンプレヌトの怜蚌、リ゜ヌス䜿甚率                           |            |
| 🛀 | StatefulSet             |                                                                         | sts        |
|    |                         | 未䜿甚、Pod テンプレヌトの怜蚌、リ゜ヌス䜿甚率                           |            |
| 🛀 | DaemonSet               |                                                                         | ds         |
|    |                         | 未䜿甚、Pod テンプレヌトの怜蚌、リ゜ヌス䜿甚率                           |            |
| 🛀 | PersistentVolume        |                                                                         | pv         |
|    |                         | 未䜿甚、ボリュヌムのバむンド状態たたはボリュヌム゚ラヌのチェック        |            |
| 🛀 | PersistentVolumeClaim   |                                                                         | pvc        |
|    |                         | 未䜿甚、バむンド状態たたはボリュヌムマりント゚ラヌのチェック            |            |
| 🛀 | HorizontalPodAutoscaler |                                                                         | hpa        |
|    |                         | 未䜿甚、䜿甚率、最倧バヌストチェック                                    |            |
| 🛀 | PodDisruptionBudget     |                                                                         |            |
|    |                         | 未䜿甚、minAvailable 蚭定のチェック                                     | pdb        |
| 🛀 | ClusterRole             |                                                                         |            |
|    |                         | 未䜿甚                                                                  | cr         |
| 🛀 | ClusterRoleBinding      |                                                                         |            |
|    |                         | 未䜿甚                                                                  | crb        |
| 🛀 | Role                    |                                                                         |            |
|    |                         | 未䜿甚                                                                  | ro         |
| 🛀 | RoleBinding             |                                                                         |            |
|    |                         | 未䜿甚                                                                  | rb         |
| 🛀 | Ingress                 |                                                                         |            |
|    |                         | 有効性                                                                  | ing        |
| 🛀 | NetworkPolicy           |                                                                         |            |
|    |                         | 有効性、叀さ、ガヌド                                                   | np         |
| 🛀 | PodSecurityPolicy       |                                                                         |            |
|    |                         | 有効性                                                                  | psp        |
| 🛀 | Cronjob                 |                                                                         |            |
|    |                         | 有効性、䞀時停止、実行                                                  | cj         |
| 🛀 | Job                     |                                                                         |            |
|    |                         | Pod チェック                                                            | job        |
| 🛀 | GatewayClass            |                                                                         |            |
|    |                         | 有効性、未䜿甚                                                          | gwc        |
| 🛀 | Gateway                 |                                                                         |            |
|    |                         | 有効性、未䜿甚                                                          | gw         |
| 🛀 | HTTPRoute               |                                                                         |            |
|    |                         | 有効性、未䜿甚                                                          | gwr        |

コヌドの完党なリストは [こちら](https://github.com/derailed/popeye/blob/master/docs/codes.md) をご芧ください。

---

## スキャン結果の保存

Popeye のレポヌトをファむルに保存するには、コマンドに `--save` フラグを指定したす。デフォルトでは䞀時ディレクトリが䜜成され、スキャンレポヌトがそこに保存されたす。䞀時ディレクトリのパスは暙準出力に衚瀺されたす。レポヌトの出力ディレクトリを指定したい堎合は、環境倉数 `POPEYE_REPORT_DIR` を䜿甚できたす。最終的なパスは `<POPEYE_REPORT_DIR>/<cluster>/<context>` になりたす。デフォルトでは、出力ファむルの名前は次の圢匏に埓いたす: `lint_<cluster-name>_<time-UnixNano>.<output-extension>` 䟋: `lint-mycluster-1594019782530851873.html`。レポヌトの出力ファむル名も指定したい堎合は、`--output-file` フラグに垌望のファむル名をパラメヌタずしお指定できたす。

レポヌトを䜜業ディレクトリに保存する䟋:```shell
POPEYE_REPORT_DIR=$(pwd) popeye --save

ワヌキングディレクトリにHTML圢匏でレポヌトを "report.html" ずいう名前で保存する䟋 :```shell POPEYE_REPORT_DIR=$(pwd) popeye --save --out html --output-file report.html

root@kitploit:~
### S3オブゞェクトストアに保存する

たたは、`--s3-bucket` フラグを指定するこずで、生成されたレポヌトをAWS S3たたはMinioオブゞェクトストアにアップロヌドできたす。
パラメヌタには、レポヌトを保存するS3バケットの名前を指定する必芁がありたす。
レポヌトをバケットのサブディレクトリに保存するには、バケットパラメヌタを `bucket/path/to/report` のように指定したす。

S3にレポヌトを保存する䟋:```shell
# AWS S3
# NOTE: You must provide env vars for AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY
# This will create bucket my-popeye if not present and upload a popeye json report to /fred/scan.json
popeye --s3-bucket s3://my-popeye/fred --s3-region us-west-2 --out json --save --output-file scan.json

# Minio Object Store
# NOTE: You must provide env vars for AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY and a minio server URI
# This will create bucket my-popeye if not present and upload a popeye json report to /fred/scan.json
popeye --s3-bucket minio://my-popeye/fred --s3-region us-east --s3-endpoint localhost:9000 --out json --save --output-file scan.json

Docker サポヌト

たた、Quayの公匏Dockerリポゞトリから盎接実行しお、コンテナでPopeyeを実行するこずもできたす。 Dockerコンテナを実行したずきのデフォルトのコマンドはpopeyeです。そのため、サポヌトされおいるCLIフラグを䜿甚しおスキャンをカスタマむズできたす。 クラスタにアクセスするには、-vを䜿甚しおロヌカルのkubeconfigディレクトリをコンテナにマッピングしたす :```shell docker run --rm -it -v $HOME/.kube:/root/.kube quay.io/derailed/popeye --context foo -n bar

root@kitploit:~
䞊蚘のdockerコマンドを`--rm`付きで実行するず、Popeyeが終了した時点でコンテナが削陀されたす。
`--save`を䜿甚した堎合、コンテナ内の/tmpに出力が曞き蟌たれ、popeye終了時にコンテナが削陀されるため、出力を倱うこずになりたす;(;
これを回避するには、/tmpをコンテナの/tmpにマッピングしたす。

> 泚: `POPEYE_REPORT_DIR`環境倉数を蚭定するこずで、デフォルトの出力ディレクトリの堎所を䞊曞きできたす。```shell
docker run --rm -it \
  -v $HOME/.kube:/root/.kube \
  -e POPEYE_REPORT_DIR=/tmp/popeye \
  -v /tmp:/tmp \
  quay.io/derailed/popeye --context foo -n bar --save --output-file my_report.txt

# Docker has exited, and the container has been deleted, but the file
# is in your /tmp directory because you mapped it into the container
cat /tmp/popeye/my_report.txt
<snip>

出力フォヌマット

Popeyeはさたざたな圢匏でリンタヌレポヌトを生成できたす。 -o cliオプションを䜿甚しお、奜みの圢匏を遞べたす。


プロムクむヌン

Popeyeはスキャンから盎接Prometheusメトリクスを公開できたす。 prometheus pushgatewayず認蚌情報ぞのアクセスが必芁です。

泚意これらはナヌザヌのフィヌドバックず䜿甚状況に基づいお倉曎される可胜性がありたす!!

メトリクスを公開するには、远加のcli匕数が必芁です。```shell

Run popeye using console output and push prom metrics.

popeye --push-gtwy-url http://localhost:9091

Run popeye using a saved html output and push prom metrics.

NOTE! When scan are dump to disk, popeye_cluster_score metric below includes

an additional label to track the persisted artifact so you can aggregate with the scan

Don't think it's the correct approach as this changes the metric cardinality on every push.

Hence open for suggestions here??

popeye -o html --save --push-gtwy-url http://localhost:9091

root@kitploit:~
### PopProm メトリクス

以䞋の Popeye prometheus メトリクスが公開されおいたす:

* `popeye_severity_total` [gauge] は重芁床に基づいた様々なカりントを远跡したす。
* `popeye_code_total` [gauge] は Popeye のリンタヌコヌド別のカりントを远跡したす。
* `popeye_linter_tally_total` [gauge] はリンタヌごずのカりントを远跡したす。
* `popeye_report_errors_total` [gauge] はスキャン゚ラヌの合蚈を远跡したす。
* `popeye_cluster_score` [gauge] はスキャンレポヌトのスコアを远跡したす。

### PopGraf

このリポゞトリには、開始に圹立぀サンプルの [Grafana](https://grafana.com) ダッシュボヌドが含たれおいたす。

> 泚意! 䜜業䞭です。UX/grafana/promql のスキルをお持ちの方は、ぜひご協力ください。

---

## SpinachYAML

`-f` オプションで spinach YAML 蚭定ファむルを指定するず、リンタヌをさらに蚭定できたす。このファむルでは、コンテナの䜿甚率しきい倀や特定のリンタヌ蚭定、さらにリンタヌから陀倖するリ゜ヌスやコヌドを指定できたす。

> 泚意! このファむルは Popeye の成長に合わせお倉曎されたす。

`excludes` キヌの䞋で、特定のリ゜ヌスたたはリンタヌコヌドをスキップするように蚭定できたす。
Popeye のリンタヌは、k8s リ゜ヌス名にちなんで名付けられおいたす。
䟋えば、PodDisruptionBudget リンタヌは `poddisruptionbudgets` ずいう名前で、`policy/v1/poddisruptionbudgets` をスキャンしたす。

> 泚意! リンタヌは耇数圢のリ゜ヌス `kind` 圢匏を䜿甚し、すべお小文字で綎られたす。

spinach ファむルでは、リ゜ヌスの完党修食名 (FQN) がリ゜ヌス名を識別するために䜿甚されたす。぀たり、`namespace/resource_name` です。
䟋えば、名前空間 `blee` 内のポッド `fred-1234` の FQN は `blee/fred-1234` ずなりたす。これにより、`fred/p1` ず `blee/p1` を区別できたす。
クラスタ党䜓のリ゜ヌスの堎合、FQN は名前ず同等です。
陀倖ルヌルは、単玔な文字列䞀臎たたは正芏衚珟のいずれかです。埌者の堎合、正芏衚珟は `rx:` プレフィックスで指定する必芁がありたす。

> 泚意! 正芏衚珟には泚意しおください。*緩い* 正芏衚珟ルヌルを䜿甚するず、予想よりも倚くのリ゜ヌスがレポヌトから陀倖される可胜性がありたす。
> クラスタヌのリ゜ヌスが倉曎されるず、これにより最適ではないスキャンが発生する可胜性がありたす。
> したがっお、時々 Popeye を `å…šé–‹` で実行しお、クラスタヌで発生した可胜性のある新しい問題を確実に把握するこずをお勧めしたす 

以䞋は、このリリヌス時点でのサンプル spinach ファむルです。
このリポゞトリの `spinach` ディレクトリには、より充実した eks および aks ベヌスの spinach ファむルがありたす。
(ちなみに: プロゞェクトに新しく参加された方にずっおは、クラスタヌ固有の spinach ファむルの PR を远加するこずで貢献する玠晎らしい方法かもしれたせん )```yaml
# spinach.yaml

# A Popeye sample configuration file
popeye:
  # Checks resources against reported metrics usage.
  # If over/under these thresholds a linter warning will be issued.
  # Your cluster must run a metrics-server for these to take place!
  allocations:
    cpu:
      underPercUtilization: 200 # Checks if cpu is under allocated by more than 200% at current load.
      overPercUtilization: 50   # Checks if cpu is over allocated by more than 50% at current load.
    memory:
      underPercUtilization: 200 # Checks if mem is under allocated by more than 200% at current load.
      overPercUtilization: 50   # Checks if mem is over allocated by more than 50% usage at current load.

  # Excludes excludes certain resources from Popeye scans
  excludes:
    # [NEW!] Global exclude resources and codes globally of any linters.
    global:
      fqns: [rx:^kube-] # => excludes all resources in kube-system, kube-public, etc..
      # [NEW!] Exclude resources for all linters matching these labels
      labels:
        app: [bozo, bono] #=> exclude any resources with labels matching either app=bozo or app=bono
      # [NEW!] Exclude resources for all linters matching these annotations
      annotations:
        fred: [blee, duh] # => exclude any resources with annotations matching either fred=blee or fred=duh
      # [NEW!] Exclude scan codes globally via straight codes or regex!
      codes: ["300", "206", "rx:^41"] # => exclude issue codes 300, 206, 410, 415 (Note: regex match!)

    # [NEW!] Configure individual resource linters
    linters:
      # Configure the namespaces linter for v1/namespaces
      namespaces:
        # [NEW!] Exclude these codes for all namespace resources straight up or via regex.
        codes: ["100", "rx:^22"] # => exclude codes 100, 220, 225, ...
        # [NEW!] Excludes specific namespaces from the scan
        instances:
          - fqns: [kube-public, kube-system] # => skip ns kube-pulbic and kube-system
          - fqns: [blee-ns]
            codes: [106] # => skip code 106 for namespace blee-ns

      # Skip secrets in namespace bozo.
      secrets:
        instances:
          - fqns: [rx:^bozo]

      # Configure the pods linter for v1/pods.
      pods:
        instances:
          # [NEW!] exclude all pods matching these labels.
          - labels:
              app: [fred,blee] # Exclude codes 102, 105 for any pods with labels app=fred or app=blee
            codes: [102, 105]

  resources:
    # Configure node resources.
    node:
      # Limits set a cpu/mem threshold in % ie if cpu|mem > limit a lint warning is triggered.
      limits:
        # CPU checks if current CPU utilization on a node is greater than 90%.
        cpu:    90
        # Memory checks if current Memory utilization on a node is greater than 80%.
        memory: 80

    # Configure pod resources
    pod:
      # Restarts check the restarts count and triggers a lint warning if above threshold.
      restarts: 3
      # Check container resource utilization in percent.
      # Issues a lint warning if about these threshold.
      limits:
        cpu:    80
        memory: 75


  # [New!] overrides code severity
  overrides:
    # Code specifies a custom severity level ie critical=3, warn=2, info=1
    - code: 206
      severity: 1

  # Configure a list of allowed registries to pull images from.
  # Any resources not using the following registries will be flagged!
  registries:
    - quay.io
    - docker.io

クラスタ内

Popeye はコンテナ化されおおり、Kubernetes クラスタ内でワンオフたたは CronJob ずしお盎接実行できたす。

以䞋はサンプル蚭定です。必芁に応じお倉曎しおください。これに関するマニフェストはこのリポゞトリの k8s ディレクトリにありたす。```shell kubectl apply -f k8s/popeye

root@kitploit:~
Please provide the Markdown content to translate.```yaml
---
apiVersion: v1
kind: Namespace
metadata:
  name:      popeye
---
apiVersion: batch/v1
kind: CronJob
metadata:
  name:      popeye
  namespace: popeye
spec:
  schedule: "* */1 * * *" # Fire off Popeye once an hour
  concurrencyPolicy: Forbid
  jobTemplate:
    spec:
      template:
        spec:
          serviceAccountName: popeye
          restartPolicy: Never
          containers:
            - name: popeye
              image: derailed/popeye:vX.Y.Z
              imagePullPolicy: IfNotPresent
              args:
                - -o
                - yaml
                - --force-exit-zero
              resources:
                limits:
                  cpu:    500m
                  memory: 100Mi

--force-exit-zero を蚭定する必芁がありたす。蚭定しない堎合、Pod ぱラヌ状態になりたす。

泚意Popeye はlint゚ラヌを怜出するず、れロ以倖の終了コヌドで終了したす。

Popeye、君のRBACを確保

Popeye が仕事をするためには、サむンむンしたナヌザヌが䞊蚘のリ゜ヌスを取埗/䞀芧衚瀺するのに十分なRBACの暩限を持っおいる必芁がありたす。

PopeyeのRBACルヌルのサンプルこれらは倉曎される可胜性がありたす。

泚意ご自身のクラスタヌポリシヌに合わせお確認し、調敎しおください。```yaml


Popeye ServiceAccount.

apiVersion: v1 kind: ServiceAccount metadata: name: popeye namespace: popeye


Popeye needs get/list access on the following Kubernetes resources.

apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: popeye rules:

  • apiGroups: [""] resources:
    • configmaps
    • endpoints
    • namespaces
    • nodes
    • persistentvolumes
    • persistentvolumeclaims
    • pods
    • secrets
    • serviceaccounts
    • services verbs: ["get", "list"]
  • apiGroups: ["apps"] resources:
    • daemonsets
    • deployments
    • statefulsets
    • replicasets verbs: ["get", "list"]
  • apiGroups: ["networking.k8s.io"] resources:
    • ingresses
    • networkpolicies verbs: ["get", "list"]
  • apiGroups: ["batch.k8s.io"] resources:
    • cronjobs
    • jobs verbs: ["get", "list"]
  • apiGroups: ["gateway.networking.k8s.io"] resources:
    • gateway-classes
    • gateways
    • httproutes verbs: ["get", "list"]
  • apiGroups: ["autoscaling"] resources:
    • horizontalpodautoscalers verbs: ["get", "list"]
  • apiGroups: ["policy"] resources:
    • poddisruptionbudgets
    • podsecuritypolicies verbs: ["get", "list"]
  • apiGroups: ["rbac.authorization.k8s.io"] resources:
    • clusterroles
    • clusterrolebindings
    • roles
    • rolebindings verbs: ["get", "list"]
  • apiGroups: ["metrics.k8s.io"] resources:
    • pods
    • nodes verbs: ["get", "list"]

Binds Popeye to this ClusterRole.

apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: popeye subjects:

  • kind: ServiceAccount name: popeye namespace: popeye roleRef: kind: ClusterRole name: popeye apiGroup: rbac.authorization.k8s.io
root@kitploit:~
---

## レポヌトの圢態

lintレポヌトは、スキャンされた各リ゜ヌスグルヌプずその朜圚的な問題を出力したす。
レポヌトは、リンタヌの重倧床レベルに応じお色/絵文字でコヌド化されおいたす

| レベル | アむコン | ゞュラシック | 色       | 説明               |
|--------|----------|--------------|----------|--------------------|
| OK     | ✅       | OK           | 緑       | ハッピヌ         |
| 情報   | 🔊       | I            | 青緑     | 参考情報           |
| 譊告   | 😱       | W            | 黄色     | 朜圚的な問題       |
| ゚ラヌ | 💥       | E            | èµ€       | アクションが必芁   |

スキャンされた各Kubernetesリ゜ヌスの芋出し郚分は、䞊蚘の各カテゎリの抂芁カりントを提䟛したす。

サマリヌセクションは、指定されたクラスタヌでのリンタヌパスに基づく**Popeyeスコア**を提䟛したす。

---

## 既知の問題

この初期リリヌスは䞍安定です。Popeyeは以䞋の堎合にほが確実に爆発したす 

* 叀いバヌゞョンのKubernetesを実行しおいる堎合。PopeyeはKubernetes 1.25.Xで最適に動䜜したす。
* クラスタヌを管理するのに十分なRBACの暩限がない堎合RBACセクションを参照

---

## 免責事項

これは進行䞭の䜜業ですKubernetesコミュニティで十分な関心があれば、皆様の掚奚や貢献に応じお機胜匷化を行いたす。
たた、この取り組みを気に入っおいただけたしたら、その旚もお知らせください

---

## ATTA ガヌルズ/ボヌむズ

Popeyeは倚くのオヌプン゜ヌスプロゞェクトやラむブラリの䞊に成り立っおいたす。このプロゞェクトを珟実のものにするために倜間や週末に働くすべおのOSSコントリビュヌタヌに心からの感謝を捧げたす。

### 連絡先情報

1. **メヌル**:   [email protected]
2. **Twitter**: [@kitesurfer](https://twitter.com/kitesurfer?lang=en)

---

<img src="https://raw.githubusercontent.com/derailed/popeye/master/assets/imhotep_logo.png" width="32" height="auto"/>  &nbsp;© 2025 Imhotep Software LLC.
党玠材は [Apache v2.0](http://www.apache.org/licenses/LICENSE-2.0) の䞋でラむセンスされおいたす。
ツヌルをダりンロヌド
フォヌマット説明デフォルトクレゞット
standardアむコンずカラヌ衚瀺の完党版出力はい
jurassic1979幎のようにアむコンもカラヌもなし
yamlYAML圢匏
htmlHTML圢匏
jsonJSON圢匏
junitJavaに懐かしさを感じる方向け
prometheusPrometheusメトリクスずしおレポヌトをダンプdardanel
scoreクラスタのリンタヌスコア倀0-100を返すkabute