## Summary - Add `compensating-controls.yaml` tracking 9 named controls that justify suppressed security findings - Update all Prowler mutelist descriptions with `CC: <id>` references to named controls - Add `mise run review-compensating-controls` task — surfaces stalest control with all codebase references - Add [[review-compensating-controls]] how-to doc - Organize Prowler and Kingfisher reports into `YYYY-MM-DD` subdirectories ### Compensating controls | ID | Mitigates | |----|-----------| | `single-user-cluster` | Image cache abuse, RBAC breadth, system pod privileges | | `tailscale-network-isolation` | Profiling endpoints, weak TLS, debug ports | | `local-registry` | AlwaysPullImages gap | | `sso-gated-admin-tools` | ArgoCD wildcard RBAC | | `operator-managed-pods` | Tailscale proxy pod security settings | | `ephemeral-privileged-jobs` | Prowler hostPID exposure | | `trusted-ci-only` | Forgejo runner DinD | | `init-container-isolation` | Grafana root init container | | `observability-stack-audit` | Missing apiserver audit logging | ## Test plan - [ ] `mise run review-compensating-controls` shows table and references - [ ] `kubectl kustomize argocd/manifests/prowler/` renders correctly - [ ] Sync prowler and kingfisher, verify next scan writes to dated subdirectory - [ ] Grep for `CC:` in mutelist files — every muted finding should have at least one 🤖 Generated with [Claude Code](https://claude.com/claude-code) Reviewed-on: #320
2.3 KiB
2.3 KiB
| title | modified | last-reviewed | tags | ||
|---|---|---|---|---|---|
| Security & Compliance | 2026-03-24 | 2026-03-24 |
|
Security & Compliance
Security posture and compliance scanning for BlumeOps infrastructure.
Compliance frameworks
| Framework | Tool | Cluster | Notes |
|---|---|---|---|
| CIS Kubernetes Benchmark v1.11 | prowler | minikube-indri | Weekly CronJob, ~82 checks |
| PCI DSS v4.0 (K8s mapping) | prowler | minikube-indri | Reuses CIS checks mapped to PCI requirements |
| ISO 27001:2022 (K8s mapping) | prowler | minikube-indri | Partial — 22 of 92 controls mapped |
Scanning tools
- prowler — CIS Kubernetes Benchmark scanner (weekly CronJob)
- deploy-prowler — deployment and ad-hoc scan how-to
- read-compliance-reports — accessing and interpreting reports
- kingfisher — Secret detection and live validation for Forgejo repos (weekly CronJob + prek hook)
Identity & access
- authentik — SSO/OIDC provider for all web services
- RBAC — Kubernetes role-based access control (audited by Prowler RBAC checks)
Network & TLS
- caddy — TLS termination for
*.ops.eblu.meservices - flyio-proxy — public ingress via Fly.io tunnel
- Tailscale — zero-trust mesh networking across all nodes
Secrets management
- 1password — root credential store
- external-secrets — Kubernetes secrets synced from 1Password
Reports
All compliance scan reports are stored on sifaka:/volume1/reports/. See read-compliance-reports for access and interpretation.
Compensating controls
Suppressed findings reference named compensating controls tracked in compensating-controls.yaml (repo root). Each control has a review date and verification steps. See review-compensating-controls for the review process.
mise run review-compensating-controls
Known gaps
- No SOC 2 compliance mapping for Kubernetes (Prowler only maps SOC 2 for AWS/Azure/GCP)
- k3s control plane checks produce no results (embedded binary, no static pods) — consider kube-bench
- Container image scanning covers
blumeops/*images only — upstream images (ollama, immich, etc.) are not scanned - IaC scanning covers the blumeops repo only — no scanning of third-party Helm charts or vendored manifests