Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
popeye — 👀 一个 Kubernetes 集群资源清理器 | Kitploit
工具/GitHubGitHub/derailed/popeye
容器安全配置审计云安全错误配置
GitHubderailed/popeye

popeye

👀 一个 Kubernetes 集群资源清理器

查看仓库网站
6.3k344211年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Popeye: Kubernetes 实时集群检查工具

Popeye 是一款实用工具,用于扫描实时 Kubernetes 集群,并报告已部署资源和配置中存在的潜在问题。 随着 Kubernetes 生态系统的增长,人类要跟踪编排集群的大量清单和策略变得越来越困难。 Popeye 基于集群中实际部署的内容进行扫描,而非磁盘上的文件。通过对集群进行代码审查,它能够检测配置错误、过时的资源,并帮助您确保遵循最佳实践,从而预防未来的问题。 它旨在减轻操作 Kubernetes 集群时面临的认知超载。 此外,如果您的集群使用了 metrics-server,它会报告潜在的资源配置过分配或欠分配问题,并在集群可能耗尽容量时尝试发出警告。

Popeye 是一个只读工具,不会以任何方式更改您的任何 Kubernetes 资源!




Go Report Card codebeat badge release license Docker Repository on Quay GitHub stars Releases


截图

控制台

JSON

HTML

Grafana 仪表盘

Popeye 发布 Prometheus 指标。我们在本仓库中提供了一个示例 Popeye 仪表盘,供您快速上手。


安装

Popeye 支持 Linux、OSX 和 Windows 平台。

  • 适用于 Linux、Windows 和 Mac 的二进制文件以 tarball 形式发布在 release 页面。

  • 对于 OSX/Unit 用户,可使用 Homebrew/LinuxBrew ```shell brew install derailed/popeye/popeye

  • 使用 go install

    go install github.com/derailed/popeye@latest
    
  • 从源码构建 Popeye 是使用 go 1.21+ 构建的。要从源码构建 Popeye,你必须:

    1. 克隆仓库

    2. 在你的 go.mod 文件中添加以下命令

      replace (
        github.com/derailed/popeye => MY_POPEYE_CLONED_GIT_REPO
      )
      
    3. 构建并运行可执行文件

      go run main.go
      

    对于没有耐心的用户,快速操作指南: ```shell

    Clone outside of GOPATH

    git clone https://github.com/derailed/popeye cd popeye

    Build and install

    make build

    Run

    popeye

PreFlight 检查

  • Popeye 使用 256 色终端模式。在 `Nix 系统上,请确保 TERM 已相应设置。

    export TERM=xterm-256color
    

命令行

你可以直接使用 Popeye,也可以通过 spinach yaml 配置文件来调整你的检查器。关于 Popeye 配置文件的详细信息如下。```shell

Dump version info and logs location

popeye version

Popeye a cluster using your current kubeconfig environment.

NOTE! This will run Popeye in the context namespace if set or like kubectl will use the default namespace

popeye

Run Popeye in the fred namespace

popeye -n fred

Run Popeye in all namespaces

popeye -A

Run Popeye uses a spinach config file of course! aka spinachyaml!

popeye -f spinach.yaml

Popeye a cluster using a kubeconfig context.

popeye --context olive

Run Popeye with specific linters and log to the console

popeye -n ns1 -s pod,svc --logs none

Run Popeye for a given namespace in a given log file and debug logs

popeye -n ns1 --logs /tmp/fred.log -v4

Stuck?

popeye help

---

## 代码检查器

Popeye 会检查你的集群,找出最佳实践和潜在问题。
目前,Popeye 只针对一组特定的 Kubernetes 资源进行检查。
更多资源即将加入!
我们希望 Kubernetes 的朋友们能贡献代码,让 Popeye 变得更好。

代码检查器的目标是发现配置错误,比如端口不匹配、死资源或未使用的资源、指标利用率、探针、容器镜像、RBAC 规则、裸资源等等。

Popeye 不是另一个静态分析工具。它会在实际集群上运行并检查 Kubernetes 资源,审计资源在野外的真实状态!

以下是部分可用代码检查器的列表:
下载工具