add Kyverno and Falco security test workloads
Kube-bench CIS scan / Scan ephemeral K3s cluster (push) Successful in 1m5s

This commit is contained in:
2026-08-14 22:08:52 -04:00
parent 2bd22db276
commit 2506b61ae0
11 changed files with 204 additions and 2 deletions
+3
View File
@@ -8,6 +8,9 @@ The default profile is 4 CPU cores, 16 GiB memory, and a 100 GiB disk. The
Ignition configuration enables Docker, creates `/opt/k3d-test/workspace`, and
installs pinned k3d and kubectl binaries on first boot.
The VM defaults to Proxmox CPU passthrough. This is important for Falco and
modern container images that require x86-64-v2 CPU features.
Enable snippets on the Proxmox storage first:
```bash