awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Back to sysdiglabs/kube-psp-advisor

Projects sharing features with Kube Psp Advisor

30 open-source projects similar to sysdiglabs/kube-psp-advisor, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.

  • aquasecurity/kubectl-who-canaquasecurity avatar

    aquasecurity/kubectl-who-can

    915View on GitHub↗

    Shows which subjects have RBAC permissions to VERB TYPE | TYPE/NAME | NONRESOURCEURL in Kubernetes.

    Go
    View on GitHub↗915
  • corneliusweig/rakkesscorneliusweig avatar

    corneliusweig/rakkess

    1,400View on GitHub↗

    Review Access - kubectl plugin to show an access matrix for server resources

    Go
    View on GitHub↗1,400
  • kubernetes-sigs/headlampkubernetes-sigs avatar

    kubernetes-sigs/headlamp

    6,729View on GitHub↗

    Headlamp is a Kubernetes web interface that runs as either a desktop application or a browser-based dashboard, providing a unified view for managing resources across multiple clusters. It supports authentication through OpenID Connect providers and kubeconfig files, and renders the UI according to the user's Kubernetes RBAC permissions, hiding or disabling actions that are not permitted. The project distinguishes itself through a plugin system that allows extending the dashboard with custom views, components, and business logic without modifying the core code. Plugins can be installed from a

    TypeScriptcloud-nativedashboarddebugging
    View on GitHub↗6,729
  • vmware-tanzu/kubeappsvmware-tanzu avatar

    vmware-tanzu/kubeapps

    5,116View on GitHub↗

    Kubeapps is a web-based application management interface for discovering, deploying, and supervising the operational lifecycle of software across one or more Kubernetes clusters. It provides a visual dashboard for orchestrating the installation and management of applications and operators, replacing manual command line operations. The project distinguishes itself through multicluster coordination, allowing users to manage applications across several distinct cluster environments from a single interface. It utilizes a software discovery system that catalogs packages from OCI-compliant containe

    Gocarveldeploymentflux
    View on GitHub↗5,116

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • feast-dev/feastfeast-dev avatar

    feast-dev/feast

    6,727View on GitHub↗

    Feast is an open-source feature store for machine learning that provides a central platform for defining, storing, and serving features across both training and inference workflows. It operates as a declarative system where feature definitions are written as code in Python files, synchronized to a central registry, and made available for low-latency online retrieval or point-in-time correct historical joins for training datasets. The project abstracts storage behind a pluggable architecture, allowing offline and online backends to be swapped without changing retrieval logic, and coordinates ma

    Pythonbig-datadata-engineeringdata-quality
    View on GitHub↗6,727
  • devtron-labs/devtrondevtron-labs avatar

    devtron-labs/devtron

    5,518View on GitHub↗

    Devtron is a Kubernetes management platform and CI/CD orchestrator designed to unify application lifecycles and infrastructure operations across multiple clusters from a single interface. It serves as a centralized dashboard for orchestrating workloads, managing security, and providing observability for Kubernetes environments. The platform distinguishes itself with a no-code workflow engine for automating container builds and software delivery pipelines, alongside a visual GitOps deployment tool for managing declarative applications and reconciling configuration drift. Its capability surfac

    Go
    View on GitHub↗5,518
  • fluxcd/flux2fluxcd avatar

    fluxcd/flux2

    7,888View on GitHub↗

    Flux is a Kubernetes GitOps delivery tool used to automate application deployments by synchronizing cluster state with configurations stored in Git, OCI, or Helm repositories. It functions as a set of controllers that monitor desired state in external sources and continuously reconcile the live cluster to match those definitions. The system distinguishes itself through a multi-cluster management plane that coordinates application delivery across fleets of remote clusters from a central hub. It provides a dedicated mechanism for automated image updates, which scans container registries for new

    Gocontinuous-deliverygitopsgitops-toolkit
    View on GitHub↗7,888
  • checkmarx/kicscheckmarx avatar

    checkmarx/kics

    2,649View on GitHub↗

    Find security vulnerabilities, compliance issues, and infrastructure misconfigurations early in the development cycle of your infrastructure-as-code with KICS by Checkmarx.

    Open Policy Agent
    View on GitHub↗2,649
  • controlplaneio/kubeseccontrolplaneio avatar

    controlplaneio/kubesec

    1,461View on GitHub↗

    Security risk analysis for Kubernetes resources

    Go
    View on GitHub↗1,461
  • cyberark/kubernetes-rbac-auditcyberark avatar

    cyberark/kubernetes-rbac-audit

    222View on GitHub↗

    Tool for auditing RBACs in Kubernetes

    Python
    View on GitHub↗222
  • cyberark/kubiscancyberark avatar

    cyberark/KubiScan

    1,428View on GitHub↗

    A tool to scan Kubernetes cluster for risky permissions

    Python
    View on GitHub↗1,428
  • darkbitio/mkitdarkbitio avatar

    darkbitio/mkit

    396View on GitHub↗

    MKIT is a Managed Kubernetes Inspection Tool that validates several common security-related configuration settings of managed Kubernetes cluster objects and the workloads/resources running inside the cluster.

    Dockerfile
    View on GitHub↗396
  • deepfence/threatmapperdeepfence avatar

    deepfence/ThreatMapper

    5,282View on GitHub↗

    ThreatMapper is a cloud native application protection platform and infrastructure security scanner. It functions as a vulnerability management system and cloud workload telemetry collector designed to monitor workloads and detect security risks across cloud and container environments. The platform distinguishes itself through a network traffic visualizer that uses machine learning to classify communication patterns and a graph-based attack mapping system to identify high-risk paths between vulnerabilities and network dependencies. Its broader capabilities cover cloud infrastructure complianc

    TypeScriptcloud-nativecloudsecuritycnapp
    View on GitHub↗5,282
  • defensia/agentD

    defensia/agent

    0View on GitHub↗
    View on GitHub↗0
  • dev-sec/cis-kubernetes-benchmarkD

    dev-sec/cis-kubernetes-benchmark

    0View on GitHub↗
    View on GitHub↗0
  • dormstern/segspecdormstern avatar

    dormstern/segspec

    15View on GitHub↗

    Static analysis from configs → Kubernetes NetworkPolicies in seconds

    Go
    View on GitHub↗15
  • external-secrets/external-secretsexternal-secrets avatar

    external-secrets/external-secrets

    6,697View on GitHub↗

    External Secrets Operator reads information from a third-party service like AWS Secrets Manager and automatically injects the values as Kubernetes Secrets.

    Goexternal-secretshacktoberfestkubernetes
    View on GitHub↗6,697
  • falcosecurity/falcofalcosecurity avatar

    falcosecurity/falco

    8,670View on GitHub↗

    Falco is an eBPF runtime security monitor and cloud native detection engine that identifies abnormal behavior and security threats across hosts and containers. It functions as a Linux kernel event auditor, capturing system calls and kernel events in real-time to detect malicious activity. The system distinguishes itself through a rule-based threat detection model that evaluates system activity against a library of community-maintained rules and custom security definitions. It enriches raw kernel events with container and Kubernetes metadata to provide observability into isolated environments

    C++cloud-nativecncfcncf-project
    View on GitHub↗8,670
  • freach/kubernetes-security-best-practicefreach avatar

    freach/kubernetes-security-best-practice

    2,712View on GitHub↗

    Kubernetes Security - Best Practice Guide

    best-practicebest-practicesguide
    View on GitHub↗2,712
  • jtblin/kube2iamjtblin avatar

    jtblin/kube2iam

    2,040View on GitHub↗

    kube2iam provides different AWS IAM roles for pods running on Kubernetes

    HTML
    View on GitHub↗2,040
  • k8scop/k8s-security-dashboardK

    k8scop/k8s-security-dashboard

    0View on GitHub↗
    View on GitHub↗0
  • keikoproj/kube-forensicskeikoproj avatar

    keikoproj/kube-forensics

    232View on GitHub↗

    kube-forensics allows a cluster administrator to dump the current state of a running pod and all its containers so that security professionals can perform off-line forensic analysis.

    Go
    View on GitHub↗232
  • kinvolk/inspektor-gadgetkinvolk avatar

    kinvolk/inspektor-gadget

    2,859View on GitHub↗

    Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF

    C
    View on GitHub↗2,859
  • kubearmor/kubearmorkubearmor avatar

    kubearmor/KubeArmor

    2,433View on GitHub↗

    KubeArmor is a runtime security enforcement system designed to protect containerized workloads and host infrastructure by restricting unauthorized process, file, and network activity. It operates by deploying lightweight agents across nodes that utilize kernel-level interception and Linux Security Modules to monitor and block system operations in real time. By mapping these enforcement actions to specific container and pod identities, the platform maintains granular access control within multi-tenant environments. The project distinguishes itself through a declarative policy orchestration fra

    Gobpfcontainersebpf
    View on GitHub↗2,433
  • kubestellar/consolekubestellar avatar

    kubestellar/console

    115View on GitHub↗

    World's first fully integrated and fully Automated Kubernetes management and orchestration solution

    TypeScript
    View on GitHub↗115
  • ladicle/kubectl-bindroleLadicle avatar

    Ladicle/kubectl-bindrole

    321View on GitHub↗

    Summarize RBAC roles for the specified subject (ServiceAccount, User and Group).

    Go
    View on GitHub↗321
  • liggitt/audit2rbacliggitt avatar

    liggitt/audit2rbac

    1,112View on GitHub↗

    audit2rbac takes a Kubernetes audit log and username as input, and generates RBAC role and binding objects that cover all the API requests made by that user.

    Go
    View on GitHub↗1,112
  • m9sweeper/m9sweeperM

    m9sweeper/m9sweeper

    0View on GitHub↗
    View on GitHub↗0
  • mhausenblas/rbac.devM

    mhausenblas/rbac.dev

    0View on GitHub↗
    View on GitHub↗0
  • nirmata/kyvernonirmata avatar

    nirmata/kyverno

    16View on GitHub↗

    Cloud Native Policy Management 🎉

    Go
    View on GitHub↗16