195eb29164846e461a04b533e783df49c4f4de94
ci / audit (push) Successful in 46s
Workstation is a k8s worker: kube-proxy hostPort rules DNAT 80/443 (any node IP + 127.0.0.1) into the ingress pod, shadowing loopback binds. Also: gvm-script target importer (63/63 imported) committed. https://projects.knownelement.com/issues/389
KNEL/compliance — compliance & security body of work
STIG/SCAP, CMMC, vulnerability management, and penetration testing for the KNEL fleet. This repo is PRIVATE — it holds vulnerability data, scan results, and security posture detail.
Goal posture (founder mandate, 2026-09-05): CMMC level 3, highest STIG profile, facility clearance track; assume constant pressure from highly skilled, well-resourced attackers. FedRAMP-style audit readiness.
Systems of record
| what | where |
|---|---|
| Redmine project | compliance-security — umbrella #311 |
| CMMC program | #452 gap analysis to CMMC L3 / facility clearance |
| Related | #382 STIG/SCAP, #389 OpenVAS/GVM on kali-tsys, #381 CIS hardening, #379 compliance test lab (sectestbed), #804 second approver |
| Discourse | https://community.turnsys.com/t/338 |
Layout (seeded 2026-09-05, growth expected)
scap/— SCAP content pipeline: ComplianceAsCode/content profiles driven through Ansible/AWX (KNELIACsecurity_scap_stigrole), OpenSCAP scanning on sectestbed first, then fleet.openvas/— Greenbone/OpenVAS on kali-tsys, inventory-fed from GLPI (#705 CMDB) so scans cover the whole fleet asset list.cmmc/— CMMC L3 roadmap, evidence structure, control mapping, reference: Kell Engineering ansible-hardening deployment guide.bor/— deploy plan for https://github.com/VuteTech/borpentest/— pentest tooling + AI-assisted testing exploration (MCP-driven frameworks vs bespoke automation over our own stack).
Working agreements
- Findings/scan output NEVER leave this repo or Redmine.
- Prod pentest activity requires an approved GLPI CR + maintenance window.
- sectestbed VMs are the first targets (see KNEL/PFVCluster change-mgmt map).
Languages
Shell
94%
Makefile
6%