Retour au classement

edgelesssys/constellation

Go

Constellation is a Kubernetes distribution for confidential computing, securing entire clusters on untrusted infrastructure. Constellation is in maintenance mode. New development continues in Contrast, which provides workload-level confidential computing using Confidential Containers. 👉 https://github.com/edgelesssys/contrast

cloud-securityconfidential-computingdata-encryptionkuberneteskubernetes-security
Croissance des étoiles
Étoiles
1.1k
Forks
62
Croissance hebdomadaire
Issues
17
4006008001k
sept. 2022déc. 2023avr. 2025juil. 2026
ArtefactsGo Modulesgo get github.com/edgelesssys/constellation
README

Constellation

Always Encrypted Kubernetes

[!IMPORTANT] Constellation is no longer actively maintained by Edgeless Systems.

This project is no longer receiving updates or support from Edgeless Systems. The repository remains available for archival purposes and community use. New development continues in Contrast, which provides workload-level confidential computing using Confidential Containers. 👉 https://github.com/edgelesssys/contrast

Govulncheck Go Report Twitter

Constellation is a Kubernetes engine that aims to provide the best possible data security. It wraps your K8s cluster into a single confidential context that is shielded from the underlying cloud infrastructure. Everything inside is always encrypted, including at runtime in memory. For this, Constellation leverages confidential computing (see the whitepaper) and more specifically Confidential VMs.

Concept

Goals

From a security perspective, Constellation is designed to keep all data always encrypted and to prevent access from the infrastructure layer (i.e., remove the infrastructure from the TCB). This includes access from datacenter employees, privileged cloud admins, and attackers coming through the infrastructure (e.g., malicious co-tenants escalating their privileges).

From a DevOps perspective, Constellation is designed to work just like what you would expect from a modern K8s engine.

Use cases

Encrypting your K8s is good for:

  • Increasing the overall security of your clusters
  • Increasing the trustworthiness of your SaaS offerings
  • Moving sensitive workloads from on-prem to the cloud
  • Meeting regulatory requirements

Features

🔒 Everything always encrypted

🔍 Everything verifiable

🚀 Performance and scale

  • High availability with multi-master architecture and stacked etcd topology
  • Dynamic cluster autoscaling with verification and secure bootstrapping of new nodes
  • Competitive performance

🧩 Easy to use and integrate

Getting started

If you're already familiar with Kubernetes, it's easy to get started with Constellation:

  1. 📦 Install the CLI or use the Terraform provider
  2. ⌨️ Create a Constellation cluster in the cloud or locally
  3. 🏎️ Run your app

Constellation Shell

Learn more: "Getting started with Constellation" videos series.

Documentation

To learn more, see the documentation. You may want to start with one of the following sections.

Support

Contributing

Refer to CONTRIBUTING.md on how to contribute. The most important points:

Warning Please report any security issue via a private GitHub vulnerability report or write to security@edgeless.systems.

License

Constellation is licensed under the Business Source License 1.1. You may use it free of charge for non-production use. You can find more information in the license section of the docs.

Dépôts similaires
mukul975/Anthropic-Cybersecurity-Skills

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

PythonPyPIApache License 2.0ai-agentsclaude-code
mahipal.engineer/Anthropic-Cybersecurity-Skills/
26.3k3.2k
wazuh/wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

C++Othersecuritycompliance
wazuh.com
16.2k2.4k
madhuakula/kubernetes-goat

Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀

HTMLMIT Licensekubernetesvulnerable-app
madhuakula.com/kubernetes-goat
5.7k1k
tenable/terrascan

Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.

GoGo ModulesApache License 2.0security-toolsinfrastructure-as-code
runterrascan.io
5.2k556
Hack-with-Github/Free-Security-eBooks

Free Security and Hacking eBooks

securityhacking
5k1.1k
Netflix/consoleme

A Central Control Plane for AWS Permissions and Access

PythonPyPIApache License 2.0aws-iamaws
3.2k281
Hacking-the-Cloud/hackingthe.cloud

An encyclopedia for offensive and defensive security knowledge in cloud native technologies.

DockerfileOtherhackingaws
hackingthe.cloud
2.7k498
BishopFox/cloudfox

Automating situational awareness for cloud penetration tests.

GoGo ModulesMIT Licenseawscloud
bishopfox.com/blog/introducing-cloudfox
2.5k250
4ndersonLin/awesome-cloud-security

🛡️ Awesome Cloud Security Resources ⚔️

securitycloud-computing
2.5k371
DataDog/stratus-red-team

:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud

GoGo ModulesApache License 2.0awsadversary-emulation
stratus-red-team.cloud
2.4k310
salesforce/cloudsplaining

Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.

JavaScriptnpmBSD 3-Clause "New" or "Revised" Licenseawsaws-iam
cloudsplaining.readthedocs.io
2.2k219
teamssix/awesome-cloud-security

awesome cloud security 收集一些国内外不错的云安全资源,该项目主要面向国内的安全人员

Apache License 2.0awesomecloud-native
wiki.teamssix.com/cloudsecurityresources/
2.1k235