valhalla94/secure-helm-flow
GitHub: valhalla94/secure-helm-flow
一个基于 Terraform 的自动化安全工具,为 AKS 上的 Docker 镜像提供漏洞扫描与策略 enforcement。
Stars: 0 | Forks: 0
# Secure Helm Flow
Terraform-based security utility for Docker vulnerability scanning and policy enforcement in AKS.
## Features
- Azure Functions triggered by DevOps webhooks for security gates
- ACR integration with AKS for private image scanning
- Azure Policy enforcement for container compliance
- Helm provider configuration for security sidecar deployment
- Log Analytics integration for vulnerability monitoring
## Usage
1. Initialize Terraform:
terraform init
2. Plan deployment:
terraform plan -var="resource_group_name=secure-helm-rg" -var="aks_name=secure-cluster" -var="acr_name=securehelmcr" -var="function_app_name=security-gate-func" -var="storage_account_name=securehelmstg" -var="log_analytics_name=securehelm-logs"
3. Apply configuration:
terraform apply
## Security Components
- **Azure Function**: Serverless security gate validating image compliance
- **Azure Policy**: Enforces security standards on AKS clusters
- **ACR**: Stores scanned images with vulnerability reports
- **AKS**: Container orchestration with integrated security monitoring
标签:ACR, AKS, Azure Container Registry, Azure Functions, Azure Kubernetes Service, Azure Policy, Azure 监控, DevOps webhook, Docker, EC2, ECS, Helm chart, Helm provider, IaC, Lerna, Log Analytics, policy enforcement, serverless 安全, sidecar, Terraform, vulnerability scanning, Web截图, 安全侧车, 安全网关, 安全门控, 安全防御评估, 容器合规, 容器安全, 容器镜像, 持续安全, 活动识别, 私有镜像仓库, 策略执行, 结构化查询, 自动化安全, 镜像扫描