mirror of
https://github.com/nubenetes/awesome-kubernetes.git
synced 2026-05-27 11:36:14 +00:00
120 KiB
120 KiB
Kubernetes Security
!!! info "Architectural Context" Detailed reference for Kubernetes Security in the context of Hardened Infrastructure.
Standard Reference
- jetstack.io: Getting started using cert-manager with the sig-network Gateway API [COMMUNITY-TOOL]
- faun.pub: External Secret Operator on AKS (with Terraform) for Azure Key' Vault Integration (with Workload Identity) [COMMUNITY-TOOL]
- Dzone - OAuth 2.0 [COMMUNITY-TOOL]
- medium: How to Harden Your Kubernetes Cluster for Production 🌟 [COMMUNITY-TOOL]
- cncf.io: Kubernetes Security 🌟 [COMMUNITY-TOOL]
- redkubes.com: 10 Kubernetes Security Risks & Best Practices [COMMUNITY-TOOL]
- blog.kasten.io: Kubernetes Ransomware Protection with Kasten K10 v4.0 [COMMUNITY-TOOL]
- levelup.gitconnected.com: Enforce Audit Policy in Kubernetes (k8s) [COMMUNITY-TOOL]
- magalix.com: Top 8 Kubernetes Security Best Practices 🌟 [COMMUNITY-TOOL]
- cncf.io: How to secure your Kubernetes control plane and node components [COMMUNITY-TOOL]
- akhilsharma.work: The 4C's of Kubernetes Security [COMMUNITY-TOOL]
- medium: Securing the Kubernetes cluster | Lessandro Z. Ugulino [COMMUNITY-TOOL]
- amazicworld.com: Top 5 security threats unique to a Kubernetes and Cloud' Native stack [COMMUNITY-TOOL]
- venturebeat.com: Kubernetes security will have a breakout year in 2022 [COMMUNITY-TOOL]
- medium: Comparing Kubernetes Security Frameworks and Guidance 🌟 [COMMUNITY-TOOL]
- blog.devgenius.io: How is security managed in Kubernetes clusters? [COMMUNITY-TOOL]
- medium.com/@jonathan_37674: Kubernetes Security Best Practices: Definitive' Guide [COMMUNITY-TOOL]
- faun.pub: From dev to admin: an easy Kubernetes privilege escalation you' should be aware of — the attack [COMMUNITY-TOOL]
- medium.com/@dotdc: Is your Kubernetes API Server exposed? Learn how to' check and fix! 🌟 [COMMUNITY-TOOL]
- levelup.gitconnected.com: The Core of Kubernetes Security: Clusters [COMMUNITY-TOOL]
- medium.com/@codingkarma: Kubernetes Goat Part-1 [COMMUNITY-TOOL]
- medium.com/@badawekoo: Limit number of processes running in a Kubernetes' pod [COMMUNITY-TOOL]
- medium.com/cloudyrion: Kubernetes end-to-end chain exploit [COMMUNITY-TOOL]
- xgrid.medium.com: Securing a Kubernetes cluster using TLS certificates' 🌟 [COMMUNITY-TOOL]
- ahmedy.hashnode.dev: Creating TLS Certificates for K8s components with OpenSSL [COMMUNITY-TOOL]
- erkanzileli.medium.com: How TLS Certificates Work [COMMUNITY-TOOL]
- medium.com/@martin.hodges: Using a wildcard certificate within your Kubernetes' cluster [COMMUNITY-TOOL]
- blog.cloudsecque.com: How to Improve the Security of Your Applications' with Kubernetes Security Scanners [COMMUNITY-TOOL]
- techmanyu.com: Kubernetes Security with Kube-bench and Kube-hunter 🌟 [COMMUNITY-TOOL]
- aninditabasak.medium.com: A Lap around Kubernetes Security & Vulnerability' scanning Tools — checkov, kube-hunter, kube-bench & Starboard [COMMUNITY-TOOL]
- towardsdev.com: 12 Scanners to Find Security Vulnerabilities and Misconfigurations' in Kubernetes [COMMUNITY-TOOL]
- faun.pub: Gatekeeper | K8 hardening backlog [COMMUNITY-TOOL]
- systemweakness.com: OWASP-K8S Security: Insecure Workload Configurations [COMMUNITY-TOOL]
- darkreading.com: Top 10 Kubernetes Security Risks Every DevSecOps Pro Should' Know [COMMUNITY-TOOL]
- Kubernetes Hardening Guidance 🌟🌟 [COMMUNITY-TOOL]
- aymen-abdelwahed.medium.com: K8s Operators — CIS Kubernetes Benchmarks [COMMUNITY-TOOL]
- medium: Working with Service Account In Kubernetes 🌟 [COMMUNITY-TOOL]
- sandeepbaldawa.medium.com: Service Accounts in K8s (Kubernetes) [COMMUNITY-TOOL]
- medium.com/pareture: Kubernetes Bound Projected Service Account Token Volumes' Might Surprise You [COMMUNITY-TOOL]
- medium.com/geekculture: K8s — ServiceAccount Token [COMMUNITY-TOOL]
- motilayo.hashnode.dev: Exploring Kubernetes Service Account Tokens and Secure' Workload Identity Federation [COMMUNITY-TOOL]
- overcast.blog: Kubernetes Service Accounts: A Practical Guide [COMMUNITY-TOOL]
- cncf.io: Revealing the secrets of Kubernetes secrets 🌟 [COMMUNITY-TOOL]
- blog.doit-intl.com: Kubernetes and Secrets Management in the Cloud [COMMUNITY-TOOL]
- medium: Kubernetes Secrets Explained [COMMUNITY-TOOL]
- medium: Managing your sensitive information during GitOps process with Secret' Sealed [COMMUNITY-TOOL]
- enlear.academy: Sealed Secrets with Kubernetes [COMMUNITY-TOOL]
- medium.com/codex: Sealed Secrets for Kubernetes [COMMUNITY-TOOL]
- carlosalca.medium.com: How to manage all my K8s secrets in git securely' with Bitnami Sealed Secrets [COMMUNITY-TOOL]
- pjame-fb.medium.com: Kubernetes Secrets from Secrets Manager using External' Secrets Operators [COMMUNITY-TOOL]
- mixi-developers.mixi.co.jp: Comparing External Secrets Operator with Secret' Storage CSI as Kubernetes External Secrets is Deprecated [COMMUNITY-TOOL]
- faun.pub: Secrets | Kubernetes [COMMUNITY-TOOL]
- medium.com/@knoldus: Using sealed secrets in Kubernetes [COMMUNITY-TOOL]
- eminalemdar.medium.com: Cloud Native Secret Management with External Secrets' Operator [COMMUNITY-TOOL]
- medium.com/google-cloud: Handle Kubernetes Secrets the GitOps Way — Part' 1 [COMMUNITY-TOOL]
- Using SSL certificates from Let’s Encrypt in your Kubernetes Ingress via cert-manager 🌟 [COMMUNITY-TOOL]
- medium: Encrypting the certificate for Kubernetes (Let’s Encrypt) 🌟 [COMMUNITY-TOOL]
- betterprogramming.pub: Kubernetes and SSL Certificate Management 🌟 [COMMUNITY-TOOL]
- faun.pub: Automate Certificate Management In Kubernetes Using Cert-Manager [COMMUNITY-TOOL]
- medium.com/@knoldus: Configure SSL certificate with cert-manager on Kubernetes [COMMUNITY-TOOL]
- blog.devgenius.io: Automated DNS/TLS with External DNS & LetsEncrypt on' Kubernetes [COMMUNITY-TOOL]
- faun.pub: Let’s encrypt and CertManager [COMMUNITY-TOOL]
- armin.su: SSL certificates from Let’s Encrypt for Kubernetes Private Ingress' via Terraform [COMMUNITY-TOOL]
- betterprogramming.pub: Kubernetes Authentication Sidecars: A Revelation' in Microservice Architecture [COMMUNITY-TOOL]
- blog.devgenius.io: SSO Authentication for Applications in Kubernetes [COMMUNITY-TOOL]
- imanishchaudhary.medium.com: Securing Kubernetes Dashboards: SSO Authentication' and RBAC Implementation with Okta and OAuth2 Proxy [COMMUNITY-TOOL]
- Configure RBAC in Kubernetes Like a Boss 🌟 [COMMUNITY-TOOL]
- Kubernetes RBAC Permission Manager 🌟 [COMMUNITY-TOOL]
- medium.com/devops-mojo: Kubernetes — Role-Based Access Control (RBAC) Overview [COMMUNITY-TOOL]
- loft-sh.medium.com: 10 Essentials for Kubernetes Access Control [COMMUNITY-TOOL]
- sumanthkumarc.medium.com: Kubernetes RBAC — Update default ClusterRoles' without editing them [COMMUNITY-TOOL]
- faun.pub: Assign permissions to an user in Kubernetes. An overview of RBAC-based' AuthZ in k8s 🌟 [COMMUNITY-TOOL]
- medium.com/@badawekoo: Using RBAC in Kubernetes for authorization-Complete' Demo-Part 1 [COMMUNITY-TOOL]
- medium.com/@15daniel10: YOYO attack on a K8S cluster [COMMUNITY-TOOL]
- medium.com/@danielepolencic: How does RBAC work in kubernetes 🌟 [COMMUNITY-TOOL]
- dominik-tornow.medium.com: Inside Kubernetes RBAC [COMMUNITY-TOOL]
- medium.com/@jtdv01: Kubernetes Authorization and Role Based Access Controls' 🌟 [COMMUNITY-TOOL]
- faun.pub: Give Users and Groups Access to Kubernetes Cluster Using RBAC [COMMUNITY-TOOL]
- medium.com/@danielepolencic: AWS IAM Roles for service accounts for on-prem' clusters [COMMUNITY-TOOL]
- medium.com/andcloudio: Setting up Authentication and RBAC Authorization' in Kubernetes [COMMUNITY-TOOL]
- medium.com/@mehmetodabashi: Authentication and Authorization in Kubernetes:' Client Certificates and Role Based Access Control (RBAC) [COMMUNITY-TOOL]
- medium.com/@brunoolimpio: Kubernetes DeepDive — Parte 2 - Kubernetes RBAC' and more... | Bruno Olimpio [COMMUNITY-TOOL]
- blog.styra.com: Why RBAC is not enough for kubernetes security 🌟🌟 [COMMUNITY-TOOL]
- medium: Single Sign-On in Kubernetes [COMMUNITY-TOOL]
- medium.com/dynatrace-engineering: Kubernetes Security Best Practices Part' 2: Network Policies [COMMUNITY-TOOL]
- medium.com/@cloud_tips: Kubernetes Security Best Practices [COMMUNITY-TOOL]
- magalix.com: kubernetes authentication 🌟 [COMMUNITY-TOOL]
- magalix.com: kubernetes authorization 🌟 [COMMUNITY-TOOL]
- lisowski0925.medium.com: Using Kubernetes Certificate Signing Requests and' RBAC for User Authentication and Authorization [COMMUNITY-TOOL]
- Kubernetes Authentication and Authorization with X509 client certificates [COMMUNITY-TOOL]
- stackoverflow: Accessing the Kubernetes REST end points using bearer token [COMMUNITY-TOOL]
- ibrahims.medium.com: Security Context — Kubernetes [COMMUNITY-TOOL]
- medium.com: Securing Kubernetes Dashboard on EKS with Pomerium [COMMUNITY-TOOL]
- mahira-technology.medium.com: Kubernetes Secrets Management: Level Up with' External Secrets Operator [COMMUNITY-TOOL]
- blog.lightspin.io: NGINX Custom Snippets CVE-2021-25742 [COMMUNITY-TOOL]
- kube-bench 🌟 ⭐ 8049 [ENTERPRISE-STABLE]
Cloud Architecture
Cloud Native Infrastructure
Ingress and API Gateways
- (2025) docs.traefik.io 🌟🌟🌟🌟 [ENTERPRISE-STABLE] — The official documentation for Traefik Proxy, showcasing a clean, production-grade implementation of MkDocs. It illustrates how complex microservice routing, TLS termination, and middleware configurations can be elegantly structured. Double-Evidence: While initially seen as a standard documentation site, live grounding shows it serves as a golden reference for structural information layout and API reference nesting in cloud-native ingress architectures.
Cloud Infrastructure
Container Runtimes
Security
- thenewstack.io: A Security Comparison of Docker, CRI-O and Containerd 🌟 [ADVANCED LEVEL] [ENTERPRISE-STABLE] — A technical comparison of the security profiles of Docker, CRI-O, and Containerd. It analyzes attack surfaces, runtime privilege enforcement, and performance implications of container-runtime interfaces (CRI) within enterprise Kubernetes setups.
Kubernetes
Education
- github.com/stackrox: Certified Kubernetes Security Specialist Study Guide' 🌟 ⭐ 429 [ADVANCED LEVEL] [COMMUNITY-TOOL] — A comprehensive community-driven study guide for the Linux Foundation's CKS exam.
- Offers curated study material on cluster setup and cluster hardening.
- Provides blueprints for microservice security, system hardening, and run-time threat detection.
- Kubernetes Goat 🌟 [ENTERPRISE-STABLE] — The premier interactive, intentionally vulnerable Kubernetes environment designed for learning cloud-native security. It features various real-world scenarios covering container escapes, SSRF, and credential harvesting, making it invaluable for security training.
Networking
- cilium.io [ADVANCED LEVEL] [DE FACTO STANDARD] — An eBPF-powered open-source project that provides high-performance, secure, and observable networking, load balancing, and network security for Kubernetes workloads. Cilium is widely adopted by enterprise platforms due to its scale capabilities and granular L3-L7 policy controls.
- itnext.io: How-To: Kubernetes Cluster Network Security 🌟 [ADVANCED LEVEL] [ENTERPRISE-STABLE] — A detailed technical guide explaining network security configurations within Kubernetes clusters. It demonstrates how to write and apply zero-trust Network Policies to restrict pod-to-pod and egress traffic effectively.
Observability
- (2022) sysdig.com: Getting started with Kubernetes audit logs and Falco 🌟 [ADVANCED LEVEL] 🌟🌟🌟🌟 [ENTERPRISE-STABLE] — An engineering guide from Sysdig illustrating how to pipeline Kubernetes audit logs into Falco for real-time threat detection.
- Details rule construction and audit filtering.
- Provides blueprint event matching for runtime anomalies and suspicious API server activities.
- Analyze Kubernetes Audit logs using Falco 🌟 [COMMUNITY-TOOL] — A hands-on open-source demonstration project for analyzing Kubernetes audit logs on lightweight K3s clusters using Falco. Ideal for dev environments and homelabs to understand security monitoring patterns.
Policy-as-Code
- Kyverno 🌟 [DE FACTO STANDARD] — A CNCF graduated Kubernetes-native policy engine.
- Allows policy definition as standard Kubernetes resources (YAML).
- Eliminates the need for complex DSLs like Rego.
- Simplifies admission control, generation, mutation, and validation of workloads.
- kyverno.io: 56 sample policies 🌟 [DOCUMENTATION] [ENTERPRISE-STABLE] — A rich library of ready-to-use Kyverno policy definitions. These templates address common cloud security standards (Pod Security Standards, multi-tenancy constraints, best practices, and resource optimization parameters) for instant cluster hardening.
Security (1)
- (2021) tldrsec.com: Risk8s Business: Risk Analysis of Kubernetes Clusters 🌟 🌟🌟🌟🌟 [ENTERPRISE-STABLE] — A security auditing guide outlining common vulnerabilities and risk assessment techniques for Kubernetes environments.
- Explores typical configuration flaws in real-world clusters.
- Analyzes overly permissive workloads and provides actionable remediation tactics for DevOps teams.
- (2021) labs.bishopfox.com: Bad Pods: Kubernetes Pod Privilege Escalation 🌟 [ADVANCED LEVEL] 🌟🌟🌟🌟 [ENTERPRISE-STABLE] — A highly regarded technical teardown of container privilege escalation paths within Kubernetes. It details how threat actors leverage misconfigured Pod Security Standards (e.g., hostPath, privileged flags, capAdd) to compromise node hosts, providing essential defense tactics.
- (2020) containerjournal.com: How to Secure Your Kubernetes Cluster 🌟 🌟🌟🌟 [COMMUNITY-TOOL] — A strategic guide to establishing cluster-wide security policies. It details the layers of security required from the underlying cloud provider network up to cluster API access, RBAC, and workload runtimes.
- (2020) cyberark.com: Attacking Kubernetes Clusters Through Your Network Plumbing: Part 1 [ADVANCED LEVEL] [COMMUNITY-TOOL] — A technical blog analyzing complex security vectors in Kubernetes CNI (Container Network Interface) plumbing.
- Details how network privilege escalation can occur via underlying CNI vulnerabilities.
- Highlights critical hardening practices for the network layer.
- Kubernetes Security Best Practices 🌟 ⭐ 2716 [COMMUNITY-TOOL] — A structured GitHub curation focusing on critical security hardening for Kubernetes clusters.
- Covers network policies and API server firewall configurations.
- Provides essential port security rules and cluster isolation tactics.
- jeffgeerling.com: Everyone might be a cluster-admin in your Kubernetes cluster [COMMUNITY-TOOL] — Jeff Geerling discusses the severe security implications of misconfigured RBAC (Role-Based Access Control) in Kubernetes. He highlights how default installations can inadvertently grant cluster-admin privileges to arbitrary service accounts, offering clear guidance on auditing and remediation.
- Microsoft.com: Attack matrix for Kubernetes 🌟 [ADVANCED LEVEL] [ENTERPRISE-STABLE] — Microsoft's foundational threat matrix for Kubernetes, modeled on the MITRE ATT&CK framework.
- Categorizes real-world threat vectors from initial access to execution.
- Provides cloud security teams with an indispensable threat modeling guide for lateral movement and cluster compromise.
- codeburst.io: 7 Kubernetes Security Best Practices You Must Follow [COMMUNITY-TOOL] — A quick-reference article outlining seven fundamental security best practices for Kubernetes. It focuses on enabling RBAC, isolating network policies, using namespaces, securing the API server, and container image scanning basics.
- thenewstack.io: Laying the Groundwork for Kubernetes Security, Across Workloads,' Pods and Users [COMMUNITY-TOOL] — An analysis of foundational Kubernetes security layers targeting workloads, pods, and user environments. It covers container runtimes, namespace isolation boundaries, and policy engines necessary to secure multi-tenant microservices setups.
- horovits.wordpress.com: Kubernetes Security Best Practices [COMMUNITY-TOOL] — A holistic compilation of security practices spanning the lifecycle of a Kubernetes cluster.
- Emphasizes shift-left container scanning.
- Focuses on Kubernetes API exposure minimization and runtime threat detection.
- kubernetes.io: Cloud native security for your clusters [COMMUNITY-TOOL] — Official Kubernetes blog overviewing the "4Cs of Cloud Native Security": Cloud, Clusters, Containers, and Code. It serves as an authoritative introduction to multi-layered cloud security hygiene and policy enforcement.
- resources.whitesourcesoftware.com: Kubernetes Security Best Practices 🌟 [COMMUNITY-TOOL] — An industry blog focusing on secure software supply chain practices within Kubernetes. It covers automating the detection of outdated libraries, scanning Docker images for CVEs, and applying security controls in CI/CD before deployment.
- thenewstack.io: Best Practices for Securely Setting up a Kubernetes Cluster [COMMUNITY-TOOL] — A practical setup guide focusing on initial bootstrap security for self-managed Kubernetes. It emphasizes disabling default service accounts, enabling TLS for all communications, and using SSH bastions for control-plane access.
- youtube: Kubernetes Security: Attacking and Defending K8s Clusters - by' Magno Logan [COMMUNITY-TOOL] — A live presentation recording demonstrating hands-on exploitation and defense tactics inside Kubernetes environments. It showcases tools like kube-hunter, kubectl abuse vectors, and configuration defense setups.
- microsoft.com: Secure containerized environments with updated threat matrix' for Kubernetes [ADVANCED LEVEL] [COMMUNITY-TOOL] — Microsoft's revised Kubernetes Threat Matrix update, detailing newly discovered tactics like credential access via cloud metadata service endpoints and API server exploitation pathways. Essential for modern security monitoring teams.
- Tetragon (Cilium) ⭐ 4691 [ADVANCED LEVEL] [DE FACTO STANDARD] [ENTERPRISE-STABLE] — An eBPF-based real-time security observability and runtime enforcement tool. Built by the creators of Cilium, Tetragon enables granular process-level, network-level, and file-level security monitoring with low performance overhead, helping to block unauthorized system actions immediately.
- thenewstack.io: Defend the Core: Kubernetes Security at Every Layer [COMMUNITY-TOOL] — A practical walkthrough of security layers within a standard Kubernetes deployment stack. It illustrates mapping defensive configurations from container code and pipelines down through the API server and network infrastructure.
- helpnetsecurity.com: Kubestriker: A security auditing tool for Kubernetes' clusters 🌟 [COMMUNITY-TOOL] — A security auditing platform review focusing on Kubestriker.
- Details how the tool scans clusters for RBAC misconfigurations.
- Pinpoints exposed endpoints and vulnerable images to provide rapid threat-vector modeling.
Cloud Native Security
Supply Chain Security
Security Tooling
- (2021) cloud.redhat.com: Top Open Source Kubernetes Security Tools of 2021 🌟🌟 [EN CONTENT] 🌟🌟🌟🌟 [ENTERPRISE-STABLE] — A strategic overview of outstanding open-source Kubernetes protection mechanisms. Summarizes and contrasts the deployment use-cases for prominent systems focused on static verification, policy governance, and kernel monitoring.
Identity and Access Management
Cloud IAM
Microsoft Entra
- Configure Microsoft Entra for Increased Security [DOCUMENTATION] [ENTERPRISE-STABLE] — Official documentation outlines hardening parameters for Microsoft Entra ID. Features prescriptive blueprints for setting up conditional access, continuous access evaluation, Multi-Factor Authentication (MFA), and role-based identity management.
Microservices
Application Lifecycle
Kubernetes Deployment
- itnext.io: Journey Of A Microservice Application In The Kubernetes World' 🌟 [EN CONTENT] [ENTERPRISE-STABLE] — Follows a microservice application from development to full-scale production deployment on Kubernetes, focusing on ingress, security, and scaling. Curator insight breaks down architectural steps, including secure service routing and config separation. Live grounding verifies that understanding the holistic life cycle helps teams avoid standard reliability bottlenecks and secure their continuous delivery setups.
Platform Security
Compliance and Auditing
Security Frameworks
- armosec.io: Kubernetes Security Compliance Frameworks 🌟 [ADVANCED LEVEL] [GUIDE] [ENTERPRISE-STABLE] [GUIDE] — Provides a thorough breakdown of standard security compliance frameworks applicable to Kubernetes environments, including CIS Benchmarks, NSA-CISA hardening guides, and MITRE ATT&CK. Details key validation metrics and remediation methods required to audit clusters against these controls.
Kubernetes Fundamentals
Security Concepts
- (2026) ==kubernetes.io: Overview of Cloud Native Security== [DOCUMENTATION] 🌟🌟🌟🌟🌟 [DE FACTO STANDARD] — The authoritative framework defining Kubernetes security architecture across the 'FourCs' Model: Cloud, Cluster, Container, and Code. Serves as the foundational blueprint for understanding attack vectors, defense-in-depth methodologies, and default-deny paradigms in orchestrating container workloads safely.
Security (2)
Access Control
Execution Control
- box/kube-exec-controller ⭐ 126 [EN CONTENT] [ADVANCED LEVEL] [COMMUNITY-TOOL] — Curator Insight: Controller to restrict and audit shell execution inside Kubernetes pods. Live Grounding: Inactive for over five years. Superseded by newer ephemeral container mechanics and modern service mesh execution boundaries.
Hardening
- marcusnoble.co.uk: Restricting cluster-admin Permissions [EN CONTENT] [ADVANCED LEVEL] [COMMUNITY-TOOL] — Curator Insight: Practical methodology for limiting root-level administrative bindings in multi-tenant environments. Live Grounding: A crucial case study showing how to configure impersonation limits and prevent privilege escalation via cluster-admin bounds.
Multi-Cluster Access
- paralus.io 🌟 [EN CONTENT] [ADVANCED LEVEL] [ENTERPRISE-STABLE] — Curator Insight: Open-source access management tool providing centralized RBAC controls for multi-cluster environments. Live Grounding: Integrates seamlessly with OIDC identity providers to enforce fine-grained access policies across diverse cloud providers.
RBAC Architecture
- (2024) ==learnk8s.io: Limiting access to Kubernetes resources with RBAC 🌟🌟🌟== [EN CONTENT] [GUIDE] 🌟🌟🌟🌟🌟 [DE FACTO STANDARD] [GUIDE] — Curator Insight: A highly visual, structured breakdown of RBAC authorization bounds. Live Grounding: LearnK8s provides precise visual guides mapping Kubernetes cluster components to API requests, forming a gold standard for authorization training.
- (2023) loft.sh: Kubernetes RBAC: Basics and Advanced Patterns [EN CONTENT] [GUIDE] 🌟🌟🌟🌟 [ENTERPRISE-STABLE] [GUIDE] — Curator Insight: Deep-dive architecture guide covering basic principles and complex patterns. Live Grounding: Explains how to scale permissions securely in multi-tenant systems using namespaces and cluster roles, backed by Loft's enterprise virtualization experience.
RBAC Auditing Tools
- Krane 🌟 ⭐ 740 [EN CONTENT] [LEGACY] — Curator Insight: An open-source Kubernetes RBAC static analysis tool designed to identify risky roles, cluster roles, and broad resource access configurations. Live Grounding: The repository is archived and inactive for over 4 years. While the structural rules engine remains historically valuable, it does not support modern Kubernetes RBAC security vectors.
- raesene.github.io: Auditing RBAC - Redux [EN CONTENT] [ADVANCED LEVEL] [ENTERPRISE-STABLE] — Curator Insight: Expert auditing analysis highlighting stealthy pathways for privilege escalation. Live Grounding: Maintained by veteran security researcher Rory McCune; covers subtle escalation exploits using system roles and custom resources.
RBAC Basics
- (2023) engineering.dynatrace.com: Kubernetes Security Best Practices -Part 1: Role Based Access Control (RBAC) [EN CONTENT] 🌟🌟🌟 [COMMUNITY-TOOL] — Curator Insight: Part 1 of Dynatrace's engineering series focusing on proper RBAC boundary creation. Live Grounding: Explains the exact telemetry impact of bad cluster role design and details methods to identify unused privileges.
- anaisurl.com: RBAC Explained with Examples 🌟 [EN CONTENT] [GUIDE] [COMMUNITY-TOOL] [GUIDE] — Curator Insight: Accessible guide explaining subjects, resources, verbs, and role bindings. Live Grounding: An ideal foundational reference with visual aids to fast-track understanding of fundamental security principles.
- dev.to: Configure RBAC in Kubernetes Like a Boss [EN CONTENT] [GUIDE] [COMMUNITY-TOOL] [GUIDE] — Curator Insight: Tactical guide detailing production-grade RBAC naming conventions and structure. Live Grounding: Features rapid-fire configurations that help bootstrap clean and audit-ready policies in dev clusters.
- youtube: Kubernetes RBAC Explained | Anton Putra 🌟 [EN CONTENT] [ENTERPRISE-STABLE] — Curator Insight: Video-based architectural guide detailing RBAC implementation. Live Grounding: Demonstrates step-by-step role construction, user mocking, and binding validation on active local clusters.
RBAC Modeling
- github.com/clvx/k8s-rbac-model: Kubernetes RBAC Model ⭐ 26 [EN CONTENT] [ADVANCED LEVEL] [COMMUNITY-TOOL] — Curator Insight: A conceptual visualization framework for modeling Kubernetes RBAC policies. Live Grounding: The project has seen zero updates in over 5 years. Deprioritized under MVQ rules due to structural obsolescence against modern apiGroups.
RBAC Resources
- rbac.dev 🌟🌟🌟 [EN CONTENT] [DOCUMENTATION] [DE FACTO STANDARD] — Curator Insight: A dedicated portal serving as a master index of guides, templates, and hardening vectors for Kubernetes RBAC. Live Grounding: Active and highly referenced by security engineers for baseline templating, simplifying the construction of least-privilege configurations.
Vulnerability Case Studies
- hackerone.com: Authenticated kubernetes principal with restricted permissions' can retrieve ingress-nginx serviceaccount token and secrets across all namespaces [EN CONTENT] [ADVANCED LEVEL] [COMMUNITY-TOOL] — Curator Insight: Security report detailing a cross-namespace privilege escalation vector in ingress-nginx. Live Grounding: Essential reading showing how service account token leaks can lead to full cluster compromise.
Authentication Protocols
Client-Side Security
- curity.io: Client Security [EN CONTENT] [ENTERPRISE-STABLE] — Analyzes security patterns and best practices for implementing secure clients within modern web architecture. Curator insight focuses on preventing token leakage on client platforms. Live grounding confirms that securing the client architecture is paramount to avoiding credential hijacking in distributed web environments.
OAuth 2.0
- curity.io: OAuth 2.0 Overview [EN CONTENT] [DE FACTO STANDARD] — An authoritative reference detailing the core flows, mechanics, and actors within the OAuth 2.0 authorization framework. Curator insight describes integration opportunities for web, native, and API client types. Live grounding demonstrates that OAuth 2.0 tokens serve as the underlying standard for authenticating microservice operations.
OIDC
- curity.io: OpenID Connect Overview [EN CONTENT] [DE FACTO STANDARD] — Provides a comprehensive introduction to OpenID Connect (OIDC), the identity layer built directly on top of OAuth 2.0. Curator insight highlights how OIDC standardizes token delivery to provide secure client identity resolution. Live grounding affirms that OIDC is the preferred mechanism for securing user access to corporate Kubernetes instances.
Certificates
Concepts
- dev.to: Kubernetes TLS, Demystified 🌟 [COMMUNITY-TOOL] — Demystifies the operational concepts of TLS, explaining how Certificate Authorities (CAs) and mutual TLS (mTLS) protect application network pathways.
Policy Enforcement
- (2025) github.com/cert-manager: Policy Approver ⭐ 90 [ADVANCED LEVEL] 🌟🌟🌟 [COMMUNITY-TOOL] — An official cert-manager approver-policy extension that verifies certificate requests against user-defined security guidelines before signing actions take place.
TLS Automation
- (2021) getbetterdevops.io: How to Secure K8S Nginx Ingress With Let’s Encrypt and Cert Manager 🌟🌟🌟 [COMMUNITY-TOOL] — Rescued guide detailing the technical orchestration steps of cert-manager and Let's Encrypt certificates mapping over NGINX Ingress controllers for ingress traffic protection.
- (2021) rejupillai.com: Let’s Encrypt the Web (for free) 🌟🌟 [COMMUNITY-TOOL] — Teaches administrators how to configure automated TLS on Google Kubernetes Engine (GKE) endpoints using GKE Ingress controllers and free Let's Encrypt certificates.
- cert-manager/cert-manager ⭐ 13830 [DE FACTO STANDARD] [ENTERPRISE-STABLE] — Consolidated record of the cert-manager project, automating dynamic certificate lifecycles to guarantee encrypted transport paths between internal microservice runtimes.
- cert-manager.io 🌟 [DOCUMENTATION] [DE FACTO STANDARD] — The main technical documentation page for cert-manager, the industry-standard PKI and TLS certificate operator for automating certificates generation and renewal.
- itnext.io: Upgrade Cert-Manager for Your Production Deployment Without Downtime [ADVANCED LEVEL] [COMMUNITY-TOOL] — Discusses upgrading cert-manager inside highly available environments without causing downtime, explaining migration mappings of CRDs and webhook components.
Cluster Hardening
Best Practices
- (2024) ==Kubernetes Security 101: Risks and 29 Best Practices 🌟== [EN CONTENT] [GUIDE] 🌟🌟🌟🌟🌟 [DE FACTO STANDARD] [GUIDE] — Curator Insight: Fundamental 101 guide compiling standard security paradigms and vectors. Live Grounding: Maintained by Red Hat; compiles 29 production-validated rules including image scanning, API isolation, and run-time container metrics.
- Amazon EKS Best Practices Guide for Security 🌟 [EN CONTENT] [ADVANCED LEVEL] [GUIDE] [DE FACTO STANDARD] [GUIDE] — Curator Insight: The definitive handbook for securing AWS EKS environments, curated by AWS security engineers. Live Grounding: Serves as the primary operational baseline for hardening network, IAM, data, and compute resources in AWS.
- thenewstack.io: 6 Kubernetes Security Best Practices 🌟 [EN CONTENT] [COMMUNITY-TOOL] — Curator Insight: Conceptual breakdown of the six pillars of native Kubernetes security. Live Grounding: Distills complicated architectures into six action items (e.g., container isolation, CIS benchmarks) for fast-growing engineering teams.
- armosec.io: Kubernetes Security Best Practices: Definitive Guide [EN CONTENT] [GUIDE] [ENTERPRISE-STABLE] [GUIDE] — Curator Insight: Comprehensive security handbook focused on practical remediation. Live Grounding: Authored by Armo (developers of Kubescape); highly detailed on network security, host configuration, and scanning orchestration.
- spectrocloud.com: Kubernetes security best practices: 5 easy ways to cut' risk [EN CONTENT] [COMMUNITY-TOOL] — Curator Insight: Architectural guide targeting five foundational risk-reduction vectors. Live Grounding: Emphasizes simple steps like node OS patching, configuration drift detection, and early pipeline policy enforcement.
Deployment Security
- (2023) semaphoreci.com: Secure Your Kubernetes Deployments [EN CONTENT] [GUIDE] 🌟🌟🌟 [COMMUNITY-TOOL] [GUIDE] — Curator Insight: Actionable patterns for securing standard Deployment manifests in CI/CD pipelines. Live Grounding: Explains key-value securityContext settings, network policy bounds, and resource allocations.
Operational Best Practices
- blog.gitguardian.com: Hardening Your Kubernetes Cluster - Guidelines (Pt.' 2) 🌟 [EN CONTENT] [ENTERPRISE-STABLE] — Part two of a comprehensive practical guide on hardening Kubernetes installations, covering advanced topics such as RBAC auditing, log aggregation, and secret encryption at rest. Curator insight addresses key steps for locking down communication channels between internal control plane services. Live grounding affirms that implementing these hardening steps drastically reduces the blast radius of compromised microservices.
Compliance Auditing
Automation
- rancher/cis-operator ⭐ 55 [COMMUNITY-TOOL] — An automated system tool to execute CIS security scans inside Rancher ecosystems. Generates custom reports mapping nodes and master components against hardened CIS standards.
Hardening (1)
- thenewstack.io: The NSA Can Help Secure Your Kubernetes Clusters [COMMUNITY-TOOL] — Provides an introductory breakdown of the NSA/CISA collaborative guidelines on hardening Kubernetes, highlighting pod security contexts, network segmentation, and system logging requirements.
- therecord.media: NSA, CISA publish Kubernetes hardening guide 🌟🌟 [ENTERPRISE-STABLE] — Reports on the publication of the joint NSA and CISA Kubernetes hardening advisory. Highlights major system recommendations to mitigate vulnerabilities associated with lateral movement and remote takeovers.
- infoq.com [COMMUNITY-TOOL] — Summarizes key operational pillars of the NSA-CISA Kubernetes hardening guide. Explains the security implications of runtime credentials, etcd access controls, and control plane settings.
- thenewstack.io: NSA on How to Harden Kubernetes [COMMUNITY-TOOL] — Breaks down NSA recommendations on securing containerized apps. Discusses runtime privileges, host isolation, and securing the internal network to prevent privilege escalations.
- armosec.io: NSA & CISA Kubernetes Hardening Guide – what is new with version' 1.1 [COMMUNITY-TOOL] — Reviews the updates introduced in version 1.1 of the NSA-CISA guide. Explains key modifications to the guidelines regarding egress traffic protection and default pod restrictions.
Standards
- kubernetes.io: Security Checklist 🌟🌟 [DOCUMENTATION] [DE FACTO STANDARD] — The official, continuously updated security checklist mapping out practices across the 4C cloud-native security model. Serves as a foundational reference for cluster hardening, namespace isolation, and API server protection.
Threat Modeling
- owasp.org: OWASP Kubernetes Top Ten [DOCUMENTATION] [DE FACTO STANDARD] — The official OWASP Kubernetes Top 10 project cataloging critical security issues. Helps engineering teams understand threat models ranging from insecure pod configurations to compromised secrets storage.
Compliance and Auditing (1)
Audit Methodology
- securitycafe.ro: A COMPLETE KUBERNETES CONFIG REVIEW METHODOLOGY [EN CONTENT] [ADVANCED LEVEL] [ENTERPRISE-STABLE] — Provides a highly detailed methodology for evaluating cluster configurations, auditing access permissions, and detecting risky configurations. Curator insight details steps for assessing RBAC mappings and node exposure. Live grounding shows that a structured configuration review is essential for passing rigorous enterprise external audits.
Compliance and Scanning
Policy Enforcement (1)
- kubescape ⭐ 11437 [ADVANCED LEVEL] [DE FACTO STANDARD] [ENTERPRISE-STABLE] — An open-source Kubernetes security platform and CNCF Sandbox project providing multi-framework compliance scanning, vulnerability assessment, and risk analysis. It automates checks against NSA-CISA, CIS benchmarks, and MITRE ATT&CK frameworks, generating detailed security posture reports. Features deep integration with CI/CD pipelines and admission controllers to enforce security-as-code.
DevSecOps
Automated Compliance
- collabnix.com: Applying DevSecOps Practices to Kubernetes [EN CONTENT] [COMMUNITY-TOOL] — Explains how to integrate DevSecOps methodologies directly into the lifecycle of containerized infrastructure. Curator insight covers pipeline integration of vulnerability scanners, registry signing, and runtime audit tools. Live grounding indicates that continuous integration of security configurations drastically reduces production attack surfaces.
CICD Pipeline Security
- (2021) infoworld.com: 10 steps to automating security in Kubernetes pipelines [EN CONTENT] 🌟🌟🌟 [COMMUNITY-TOOL] — Focuses on establishing highly automated security checkpoints across the continuous delivery pipeline. Curator insight lists key automation areas, including infrastructure-as-code linting and automated vulnerability patching. Live grounding proves that shifting security left into the pipeline minimizes runtime surprises and maintains continuous developer velocity.
SAST
- GitHub Code Security Risk Assessment: Free Vulnerability Scanning [EN CONTENT] [COMMUNITY-TOOL] — An introduction to GitHub's native, free vulnerability scanning tools designed to locate security regressions, secrets, and supply chain threats directly within the code repository. It highlights automated security alerts and quick enablement configurations.
Static Code Analysis
- itnext.io: Performing Security Checks for Deployed Kubernetes Manifests [EN CONTENT] [ENTERPRISE-STABLE] — Outlines methods and tools used to inspect existing, live-running, or static Kubernetes resource manifests for structural defects. Curator insight showcases policy enforcement tools such as Checkov and Kube-score. Live grounding demonstrates that shift-left auditing of manifests in CI guarantees that only vetted resources enter production.
Endpoint and Client Security
Kubeconfig Hardening
- gist.github.com: How to protect your ~/.kube/ configuration [EN CONTENT] [COMMUNITY-TOOL] — This Gist provides practical configuration steps to protect the local
~/.kube/configfile from unauthorized access. Curator insight highlights standard file permissions (chmod 600), while live grounding demonstrates how local credential storage remains a high-value target for workstation compromise. The guide outlines methods to secure context credentials, including token helpers and shell env configurations.
Foundational Concepts
Cluster Hardening (1)
- thenewstack.io: How to Secure Kubernetes, the OS of the Cloud [EN CONTENT] [COMMUNITY-TOOL] — Compares the security architecture of Kubernetes to traditional operating systems, identifying the key layers requiring abstraction-level security. Curator insight advocates for a shift in perspective, treating API access as the primary security perimeter. Live grounding supports that defense-in-depth must encompass the host, container, and API boundary to form a resilient cloud-native posture.
- cast.ai: Kubernetes Security: 10 Best Practices from the Industry and' Community 🌟 [EN CONTENT] [ENTERPRISE-STABLE] — Synthesizes expert advice and industry-proven practices for comprehensive cluster defense. Curator insight focuses on the absolute necessity of etcd encryption, regular posture checks, and network policies. Live grounding highlights that combining these strategies creates a multi-layered shield that significantly increases attackers' efforts.
- itnext.io: Introduction to Kubernetes Security for Security Professionals [EN CONTENT] [ENTERPRISE-STABLE] — Bridges the gap between traditional security methodologies and cloud-native container structures for cybersecurity practitioners. Curator insight maps standard risk controls to container security contexts, networking policies, and etcd encryption. Live grounding reveals that security professionals must master APIs and declarative states to implement automated assurance.
Future of Security
- thenewstack.io: Basic Principles Key to Securing Kubernetes’ Future [EN CONTENT] [COMMUNITY-TOOL] — Discusses evolutionary principles designed to ensure the long-term robustness of cloud-native systems. Curator insight stresses the necessity of secure-by-default configurations and standardized API control planes. Live grounding supports that reducing cognitive load for operators through self-healing security layers represents the future of secure operations.
Introductory Security
- dev.to/mattiasfjellstrom: Kubernetes-101: Security concepts [EN CONTENT] [COMMUNITY-TOOL] — Explains introductory security concepts in Kubernetes, targeting beginner operators and developers. Curator insight highlights the core mechanisms of namespace separation, RBAC roles, and container Isolation. Live grounding confirms that a strong grasp of these fundamental concepts is required before implementing advanced security meshes.
The 4Cs model
- dev.to/thenjdevopsguy: The 4 C’s Of Kubernetes Security [EN CONTENT] [COMMUNITY-TOOL] — An educational guide summarizing the security dimensions defined by the CNCF '4C' model: Cloud, Cluster, Container, and Code. Curator insight outlines actionable steps to secure each layer. Live grounding confirms that systemic failure at any single layer exposes the entire cluster architecture to risk.
Threat Landscape
- thenewstack.io: Securing Kubernetes in a Cloud Native World [EN CONTENT] [LEGACY] — Surveys the shifting landscape of threat profiles in modern distributed cloud environments. Curator insight explores how legacy perimeter security controls fail inside highly dynamic container environments. Live grounding reinforces the importance of using identity-driven workload authorization and fine-grained access limits.
Identity Management
Authentication Protocols (1)
- (2024) Implementing a custom Kubernetes authentication method [EN CONTENT] [ADVANCED LEVEL] [GUIDE] 🌟🌟🌟🌟 [ENTERPRISE-STABLE] [GUIDE] — Curator Insight: Highly technical tutorial on implementing custom authentication handlers. Live Grounding: Covers custom webhooks, custom token caching, and request inspection patterns for unique security infrastructures.
- goteleport.com: A Simple Overview of Authentication Methods for Kubernetes' Clusters [EN CONTENT] [COMMUNITY-TOOL] — Curator Insight: Broad examination of OIDC, X.509 client certs, and webhook authenticators. Live Grounding: A high-density conceptual summary simplifying the choices for enterprise identity providers.
- kubernetes.io: Authenticating [EN CONTENT] [DOCUMENTATION] [DE FACTO STANDARD] — Curator Insight: Official Kubernetes reference documentation for cluster-wide authentication mechanisms. Live Grounding: Absolute source of truth covering token methods, client certificates, and webhook protocols for API traffic control.
- kubernetes login [EN CONTENT] [GUIDE] [ENTERPRISE-STABLE] [GUIDE] — Curator Insight: Practical deep dive by Christian Posta detailing kubectl token flow and login mechanisms. Live Grounding: Explains underlying client certificate and token caching, helping developers debug authorization blockages.
- OpenID Connect [EN CONTENT] [ADVANCED LEVEL] [DOCUMENTATION] [DE FACTO STANDARD] — Curator Insight: Home of the OpenID Connect federation standard, which acts as the foundation for Kubernetes authentication. Live Grounding: Critical global standard underpinning identity validation in modern cloud architecture.
Cloud Integration
- dev.to: Binding AWS IAM roles to Kubernetes Service Account for on-prem' clusters | Daniele Polencic 🌟 [EN CONTENT] [ADVANCED LEVEL] [GUIDE] [ENTERPRISE-STABLE] [GUIDE] — Curator Insight: Technical guide on binding AWS IAM roles directly to ServiceAccounts inside on-premises nodes. Live Grounding: Offers an architecturally sound pattern for managing hybrid cloud identity federations without static AWS keys.
- From Zero to Hero with Identity and Access Control in Azure Kubernetes Service [EN CONTENT] [ADVANCED LEVEL] [GUIDE] [ENTERPRISE-STABLE] [GUIDE] — Curator Insight: Architect blueprint for managing Microsoft Entra ID integration in Azure Kubernetes Service. Live Grounding: Walks through configuring fine-grained identity federation and replacing Kubernetes cluster roles with enterprise Azure AD mappings.
Enterprise Authentication
- (2023) gravitational.com: How to Set Up Kubernetes SSO with SAML [EN CONTENT] [ADVANCED LEVEL] [GUIDE] 🌟🌟🌟🌟 [ENTERPRISE-STABLE] [GUIDE] [LEGACY] — Curator Insight: Tutorial showing how to secure the Kubernetes API utilizing SAML Single Sign-On. Live Grounding: Details proxy setup and Dex configuration, bridging legacy authentication methods with modern web authorization engines.
- (2023) loft.sh: Kubernetes and LDAP: Enterprise Authentication for Kubernetes [EN CONTENT] [GUIDE] 🌟🌟🌟 [COMMUNITY-TOOL] [GUIDE] — Curator Insight: Deep dive into linking LDAP catalogs with Kubernetes authorization planes. Live Grounding: Focuses on authentication bridging patterns, helping enterprise operators synchronize Active Directory mappings safely.
Microservice Identities
- (2024) ==learnk8s.io: Authentication between microservices using Kubernetes identities 🌟== [EN CONTENT] [ADVANCED LEVEL] [GUIDE] 🌟🌟🌟🌟🌟 [DE FACTO STANDARD] [GUIDE] — Curator Insight: Deep guide on binding Pod identities to external identity systems for service-to-service validation. Live Grounding: Critical reference detailing token volume projection and secure microservices cross-boundary authentication workflows.
Identity and Access
API Security
- devopscube.com: How To Create Kubernetes Service Account For API Access [COMMUNITY-TOOL] [GUIDE] — Provides a direct guide on setting up Service Accounts, defining authorization rules using RoleBindings, and managing modern TokenRequest APIs for microservice access.
- github.com/dvob/k8s-s2s-auth: Kubernetes Service Accounts 🌟 [LEGACY] — Demonstrates internal service-to-service auth patterns utilizing raw Service Account tokens. Note: The repository has seen no recent development and is considered legacy under MVQ rules.
- gini/dexter ⭐ 168 [LEGACY] — An OIDC-helper CLI tool for generating kubectl credential configurations. Inactive for over 4 years; considered legacy under Nubenetes MVQ rules.
Access Control (1)
- geek-cookbook.funkypenguin.co.nz: Using OAuth2 proxy for Kubernetes Dashboard [COMMUNITY-TOOL] — Shows how to secure access to the default Kubernetes Dashboard using OAuth2-Proxy combined with modern enterprise Identity Providers.
- infracloud.io: How to setup Role based access (RBAC) to Kubernetes Cluster' 🌟 [ENTERPRISE-STABLE] — A deep dive tutorial explaining Role-Based Access Control (RBAC) configurations, highlighting how to design custom Roles, ClusterRoles, and user bindings.
Cloud Integrations
- mjarosie.github.io: IAM roles for Kubernetes service accounts - deep dive [ADVANCED LEVEL] [COMMUNITY-TOOL] — An in-depth guide on AWS IAM Roles for Service Accounts (IRSA). Demystifies OIDC authentication mechanics and explains how the control plane maps AWS roles to local pods.
Hardening (2)
- blog.gitguardian.com: Kubernetes Hardening Tutorial Part 3: Authn, Authz,' Logging & Auditing [COMMUNITY-TOOL] — Explains setup routines for Authentication, RBAC systems, and event logging patterns. Demonstrates how proper audit streams act as reactive verification layers against security threats.
Workload Identity
- (2024) ==learnk8s.io/authentication-kubernetes: User and workload identities in Kubernetes 🌟🌟🌟== [GUIDE] 🌟🌟🌟🌟🌟 [DE FACTO STANDARD] [GUIDE] — A deep dive comparing human user logins and system-managed Service Accounts. Walks through the mechanics of token verification and the internal request protocols of the API server.
- (2021) linkerd.io: Using Kubernetes's new Bound Service Account Tokens for secure workload identity 🌟🌟🌟🌟 [ENTERPRISE-STABLE] — Describes how Linkerd leverages Bound Service Account Tokens to construct cryptographic workload identity, showing their security advantages over older token mechanisms.
Identity and Access Management (1)
API Server Hardening
- goteleport.com: Kubernetes API Access Security Hardening [EN CONTENT] [ADVANCED LEVEL] [ENTERPRISE-STABLE] — High-fidelity instructions on securing access to the Kubernetes API server, emphasizing the dangers of exposed endpoints. Curator insight focuses on eliminating permanent credentials in favor of short-lived, role-based certificates. Live grounding demonstrates that protecting the API gateway via proxy solutions and strict IP whitelisting prevents critical control plane compromises.
Access Control (2)
- thenewstack.io: Cloud Native Identity and Access Management in Kubernetes [EN CONTENT] [ADVANCED LEVEL] [ENTERPRISE-STABLE] — Examines identity federation, user access management, and internal service-to-service authentication models. Curator insight details mapping cluster roles directly to organizational single sign-on identities. Live grounding indicates that decentralized identity and modern authentication are critical to maintaining least privilege in high-scale infrastructure.
Single Sign-On
- (2021) talkingquickly.co.uk: Kubernetes Single Sign On - A detailed guide 🌟 [EN CONTENT] [ADVANCED LEVEL] 🌟🌟🌟 [COMMUNITY-TOOL] — Outlines the end-to-end integration of external identity providers (IdPs) with the Kubernetes API server using OpenID Connect (OIDC). Curator insight guides through configuring API server flags and utilizing helper tools like Gangway or dex. Live grounding establishes that integrating external OIDC is a critical security step for mapping enterprise roles to Kubernetes RBAC.
- dev.to/gabrielbiasi: Automatic SSO in Kubernetes workloads using a sidecar' container [EN CONTENT] [ENTERPRISE-STABLE] — Explains how to offload authentication requirements from applications by wrapping workloads with a sidecar proxy. Curator insight details setting up proxies like OAuth2 Proxy or Keycloak Gatekeeper. Live grounding confirms that sidecar patterns enable centralized single sign-on without changing application code.
Industry Reports
Threat Landscape (1)
- redhat.com: The State of Kubernetes Security [EN CONTENT] [COMMUNITY-TOOL] — This Red Hat analysis outlines prevalent vulnerabilities, configuration errors, and runtime threats observed in enterprise container environments. Curator insight focuses on the dominance of misconfigurations as the primary cause of security incidents. Live grounding demonstrates that software supply chain issues and runtime security are increasingly challenging for modern enterprises.
- redhat.com: State of Kubernetes Security Report - Spring 2021 (PDF) 🌟 [EN CONTENT] [COMMUNITY-TOOL] — An extensive ebook documenting industry security adoption rates, primary concerns, and threat behaviors in Spring 2021. Curator insight highlights that container configuration defects remain the highest source of corporate security anxiety. Live grounding confirms the trends predicted in this report have materialized in modern zero-trust control planes.
Infrastructure Security
API Gateway Access
- kubernetes.io: Access Clusters Using the Kubernetes API [EN CONTENT] [DOCUMENTATION] [DE FACTO STANDARD] — Curator Insight: Official upstream tasks covering direct API server communication pathways. Live Grounding: Teaches developers and automated CI systems how to authenticate and safely dispatch requests directly to API server endpoints.
Cluster Control Plane
- kubernetes.io: Accesing Clusters [EN CONTENT] [DOCUMENTATION] [DE FACTO STANDARD] — Curator Insight: Official documentation on general cluster gateway entry points. Live Grounding: Primary map for developers, operators, and tools to locate endpoints and pass initial authentication handshakes.
Network Protection
- (2025) Calico in EKS [EN CONTENT] [DOCUMENTATION] 🌟🌟🌟🌟 [ENTERPRISE-STABLE] — Curator Insight: Official AWS guide to configuring Calico as a network policy engine within EKS clusters. Live Grounding: Standard pattern for implementing namespace segregation and network isolation for microservices.
- Building a DDoS Response Plan with Azure DDoS Protection [EN CONTENT] [COMMUNITY-TOOL] — Curator Insight: Architecture plan to withstand high-volume distributed denial-of-service attempts. Live Grounding: Focuses heavily on cloud-native patterns like rate-limiting, load-balancer protection, and Edge integration on Azure platforms.
- Security Group Rules EKS [EN CONTENT] [DOCUMENTATION] [ENTERPRISE-STABLE] — Curator Insight: Official AWS guidelines on minimal security group parameters for EKS control planes and workers. Live Grounding: Vital infrastructure design reference preventing accidental exposure of internal cluster controllers.
- EC2 ENI and IP Limit [EN CONTENT] [DOCUMENTATION] [ENTERPRISE-STABLE] — Curator Insight: Technical documentation specifying ENI limits and IP exhaustion thresholds in EC2. Live Grounding: Critical reference for EKS network planning to avoid pod startup errors due to IP scarcity.
Vulnerability Intelligence
- kubernetes.io: Official CVE Feed 🌟 [EN CONTENT] [DOCUMENTATION] [DE FACTO STANDARD] — Curator Insight: Upstream Kubernetes project tracking CVE announcements and security advisories. Live Grounding: The authoritative source of vulnerability data necessary for building compliance scans and security guardrails.
Zero Trust
- thenewstack.io: Securing Access to Kubernetes Environments with Zero Trust [EN CONTENT] [COMMUNITY-TOOL] — Curator Insight: Article on applying Zero Trust Network Access (ZTNA) parameters to cluster control planes. Live Grounding: Covers contextual authorization and micro-segmentation workflows designed to replace static kubeconfig files.
Network Security
Network Policies
- tigera.io: Kubernetes security policy design: 10 critical best practices' 🌟 [EN CONTENT] [ENTERPRISE-STABLE] — A structured set of recommendations for designing resilient network and security policies. Curator insight advises transitioning from flat networks to zero-trust micro-segmentation. Live grounding reveals that enforcing default-deny ingress and egress rules at the CNI layer is paramount for restricting lateral movement during an active compromise.
Network Segmentation
- blog.gitguardian.com: Kubernetes Hardening Tutorial Part 2: Network [EN CONTENT] [COMMUNITY-TOOL] — Delves into network-level security configurations, detailing how to implement namespace isolation and default-deny policies. Curator insight highlights key methods for controlling egress traffic to prevent external exfiltration. Live grounding demonstrates that CNI-enforced policies are fundamental for limiting the spread of attacks within multi-tenant clusters.
Public Exposure
- raesene.github.io: Let's talk about Kubernetes on the Internet [COMMUNITY-TOOL] — Analyzes the operational and security implications of exposing Kubernetes API servers directly to the public internet. Discusses real-world scanning threats and mitigation options like firewalling, OIDC, and endpoint protection.
Threat Intelligence
- (2022) blog.cyble.com: Exposed Kubernetes Clusters 🌟🌟 [COMMUNITY-TOOL] — A threat analysis analyzing the exposure of insecure Kubernetes endpoints on the public web. Details common scanning methods and real-world exploitation frameworks targeting raw, unauthenticated APIs.
Zero Trust Architecture
- (2022) copado.com: Applying a Zero Trust Infrastructure in Kubernetes [EN CONTENT] [ADVANCED LEVEL] 🌟🌟🌟 [COMMUNITY-TOOL] — Outlines architectural models for establishing zero-trust policies inside dynamic container structures. Curator insight points to identity-driven micro-segmentation and continuous token validation at each boundary. Live grounding shows that using service meshes (like Istio or Linkerd) simplifies enforcing mutual TLS and granular authorization policies.
Policy Enforcement (2)
Admission Control
- itnext.io: Kubernetes OWASP Top 10: Centralised Policy Enforcement [ADVANCED LEVEL] [COMMUNITY-TOOL] — Discusses integrating centralized admission control policies (like OPA/Gatekeeper or Kyverno) to mitigate OWASP Kubernetes Top 10 vulnerabilities. Explains how structural constraints on manifests prevent downstream security bypasses.
- trstringer.com: Create a Basic Kubernetes Validating Webhook [EN CONTENT] [ADVANCED LEVEL] [GUIDE] [ENTERPRISE-STABLE] [GUIDE] — Curator Insight: Developer guide demonstrating how to build, deploy, and register a custom validating webhook in Go. Live Grounding: Essential practical reference for building guardrails directly on top of the Kubernetes API server admission phase.
Manifest Auditing
- blog.frankel.ch: Learning by auditing Kubernetes manifests [EN CONTENT] [GUIDE] [ENTERPRISE-STABLE] [GUIDE] — Curator Insight: Unique learning methodology based on static code analysis of raw Kubernetes manifests. Live Grounding: Teaches engineers how to spot structural vulnerabilities (e.g., hostPath mounts, root privileges) before applying resources.
Policy Engines
- Neon Mirrors: Kubernetes Policy Comparison: OPA/Gatekeeper vs Kyverno [EN CONTENT] [ADVANCED LEVEL] [ENTERPRISE-STABLE] — Curator Insight: Detailed evaluation comparing the design paradigms, language limits, and performance of OPA/Gatekeeper versus Kyverno. Live Grounding: Provides objective architectural data comparing Rego-based policies to native YAML definitions.
Runtime Security
- (2021) Pod Security Policy (SCC in OpenShift) 🌟 [EN CONTENT] [DOCUMENTATION] 🌟 [LEGACY] — Curator Insight: Deprecated native resource that defined security profiles for pod execution. Live Grounding: Completely removed in Kubernetes v1.25. Replaced globally by Pod Security Standards (PSS) and third-party validation engines.
- (2021) rancher.com: Enhancing Kubernetes Security with Pod Security Policies, Part 1 [EN CONTENT] [GUIDE] 🌟 [GUIDE] [LEGACY] — Curator Insight: Part 1 of SUSE Rancher's historical guide to restricting root access through PSPs. Live Grounding: Useful exclusively for managing legacy clusters. Unusable on modern Kubernetes releases.
- developer.squareup.com: Kubernetes Pod Security Policies (PSP) [EN CONTENT] [ADVANCED LEVEL] [GUIDE] [COMMUNITY-TOOL] [GUIDE] — Curator Insight: Historical engineering post detailing Square's journey implementing early-generation PSP blocks. Live Grounding: Excellent case study for understanding design challenges but completely obsolete.
- itnext.io: Implementing a Secure-First Pod Security Policy Architecture [EN CONTENT] [GUIDE] [COMMUNITY-TOOL] [GUIDE] — Curator Insight: Practical implementation guide for designing restricted PSP parameters. Live Grounding: Highly detailed historically, but lacks application in modern environments where PSS or Kyverno is required.
- kubernetes-sigs/security-profiles-operator ⭐ 846 [EN CONTENT] [ADVANCED LEVEL] [ENTERPRISE-STABLE] — Curator Insight: Kubernetes SIG operator for managing AppArmor, Seccomp, and SELinux profiles natively within clusters. Live Grounding: Fully active and widely used in secure sectors to harden container execution boundaries.
- kubernetes.io: What's new in Security Profiles Operator v0.4.0 [EN CONTENT] [ENTERPRISE-STABLE] — Curator Insight: Upstream release notes detailing critical profiles expansion inside the Security Profiles Operator. Live Grounding: Explains runtime metrics tracking and automated profile recording functions.
Runtime Observability
eBPF Threat Detection
- isovalent.com: Detecting a Container Escape with Cilium and eBPF [EN CONTENT] [ADVANCED LEVEL] [DE FACTO STANDARD] — A deep-dive exploration of container escape methodologies and how they can be detected at the kernel layer using Cilium and eBPF. Curator insight focuses on monitoring system calls directly to bypass container-internal obfuscation. Live grounding confirms that eBPF observability provides the low-overhead, high-fidelity metrics needed to identify escape payloads before damage occurs.
- developers.redhat.com: Secure your Kubernetes deployments with eBPF [EN CONTENT] [ADVANCED LEVEL] [ENTERPRISE-STABLE] — Technical article explaining the operational advantages of using eBPF for cloud-native workload defense. Curator insight explains how eBPF operates safely within the Linux kernel to record and control system behavior without sidecars. Live grounding confirms that eBPF technology has transitioned from a monitoring utility to a standard tool for runtime security.
Runtime Security (1)
Threat Detection
- (2022) infoworld.com: The race to secure Kubernetes at run time [EN CONTENT] 🌟🌟🌟 [COMMUNITY-TOOL] — Explores the rapid evolution of security technologies focusing on runtime detection and container-level process isolation. Curator insight details the industry transition away from simple static analysis toward active behavioral profiling. Live grounding confirms that eBPF-driven insights and real-time enforcement have become critical standards for identifying novel zero-day threats.
Secret Management
Certificate Management
- blog.alexellis.io: What if your Pods need to trust self-signed certificates? [EN CONTENT] [ENTERPRISE-STABLE] — Evaluates options for mounting and trusting custom or self-signed Root Certificate Authorities (CAs) inside container environments. Curator insight shows practical configurations for injecting custom root stores through init containers or volume mounts. Live grounding confirms that managing private PKIs is crucial for microservices in secure enterprise intranets.
- thenewstack.io: Jetstack Secure Promises to Ease Kubernetes TLS Security [EN CONTENT] [ADVANCED LEVEL] [ENTERPRISE-STABLE] — Analyzes Jetstack Secure, an enterprise platform wrapping the open-source cert-manager tool to orchestrate certificates. Curator insight details how this service helps operationalize automated certificate renewal across multi-cluster environments. Live grounding confirms that automated PKI management reduces manual oversight and cuts down on unexpected service outages.
HashiCorp Vault
- (2023) ==learn.hashicorp.com: Integrate a Kubernetes Cluster with an External Vault 🌟== [EN CONTENT] [ADVANCED LEVEL] 🌟🌟🌟🌟🌟 [DE FACTO STANDARD] [GUIDE] — Step-by-step tutorial on integrating Kubernetes secrets management with an external HashiCorp Vault instance. Curator insight shows how to securely inject secrets using the Vault Agent injector sidecar. Live grounding confirms that externalized secret managers are an industry standard for multi-tenant, enterprise-grade clusters in order to avoid native etcd secrets exposure.
Secrets Management
Automation (1)
- youtube: Manage Kubernetes Secrets With External Secrets Operator (ESO)' 🌟 [ENTERPRISE-STABLE] — A video walk-through of the External Secrets Operator (ESO). Explains how to orchestrate automated synchronization between external secrets engines and native Kubernetes workflows.
Cloud Integrations (1)
- (2025) Four Methods to Access Azure Key Vault from Azure Kubernetes Service (AKS) 🌟🌟🌟 [COMMUNITY-TOOL] — Evaluates four approaches to integrate Azure Key Vault secrets within AKS environments. Weighs security architectures including Azure Workload Identity and the Secrets Store CSI driver.
- itnext.io: Effective Secrets with Vault and Kubernetes [COMMUNITY-TOOL] — Explains HashiCorp Vault integration inside Kubernetes environments. Illustrates the Vault Agent Sidecar Injector mechanism, allowing target workloads to resolve credentials directly.
- itnext.io: Vault cluster with auto unseal on Kubernetes [ADVANCED LEVEL] [COMMUNITY-TOOL] — Details the configurations needed to bootstrap highly available HashiCorp Vault systems using dynamic KMS systems (AWS or GCP) to automate unsealing tasks.
Compliance Auditing (1)
- itnext.io: Kubernetes OWASP Top 10: Secrets Management [COMMUNITY-TOOL] — Deals with risks concerning exposed credentials and hardcoded parameters within Kubernetes workflows. Walks through mitigation setups in compliance with OWASP guidelines to prevent secrets leakage.
Concepts (1)
- (2021) millionvisit.blogspot.com: Kubernetes for Developers #19: Manage app credentials using Kubernetes Secrets 🌟 🌟🌟 [COMMUNITY-TOOL] — A developer-centric tutorial on provisioning, managing, and consuming API credentials using core Secrets configurations in single-tenant applications.
- enterprisersproject.com: How to explain Kubernetes Secrets in plain English' 🌟 [COMMUNITY-TOOL] — An easy-to-follow introductory resource explaining Kubernetes Secrets, their typical configuration schemas, and how they help developers protect operational application parameters.
- kubermatic.com: Keeping the State of Apps Part 2: Introduction to Secrets [COMMUNITY-TOOL] — Introduces key concepts of stateful configuration security. Analyzes how secrets are handled internally by API controllers and mounted securely on ephemeral container systems.
- macchaffee.com: Plain Kubernetes Secrets are fine 🌟 [ENTERPRISE-STABLE] — Offers an alternative perspective arguing that built-in Kubernetes secrets are adequate for standard environments when combined with strong RBAC and locked-down etcd storage.
Data Protection
- kubernetes.io: Encrypting Secret Data at Rest 🌟 [ADVANCED LEVEL] [DOCUMENTATION] [ENTERPRISE-STABLE] — The official documentation guiding system admins through encrypting etcd secret data at rest. Covers local secrets key providers and external KMS plugin configurations.
Discussion
- (2022) Kubernetes base64 encodes secrets because that makes arbitrary data play nice with JSON. It had nothing to do with the security model (or lack thereof).' It did not occur to us at the time that people could mistake base64 for some form of encryption 🌟🌟🌟 [COMMUNITY-TOOL] — A multi-perspective community debate focusing on Base64 encoding in secrets. Reinforces that encoding is not encryption and underlines the absolute need for robust encryption-at-rest configurations.
GitOps
- (2021) cloud.redhat.com: A Guide to Secrets Management with GitOps and Kubernetes 🌟 🌟🌟🌟🌟 [ENTERPRISE-STABLE] — An architectural review of credentials handling within declarative GitOps systems. Evaluates and compares Sealed Secrets with dynamic external resolution services.
- dev.to: Store your Kubernetes Secrets in Git thanks to Kubeseal. Hello SealedSecret!' 🌟 [COMMUNITY-TOOL] — Introduces Bitnami's Sealed Secrets (kubeseal), highlighting how asymmetric public-key cryptography allows engineers to securely check encrypted credentials into public Git setups.
- piotrminkowski.com: Sealed Secrets on Kubernetes with ArgoCD and Terraform [ADVANCED LEVEL] [COMMUNITY-TOOL] — Demonstrates a production GitOps configuration combining Bitnami Sealed Secrets, Terraform, and ArgoCD to deploy securely encrypted config files.
Integration Tools
- external-secrets.io 🌟 [EN CONTENT] [DE FACTO STANDARD] — Curator Insight: Industry-standard controller designed to inject secrets securely into clusters from external providers. Live Grounding: Highly active; supports AWS, GCP, Azure, and HashiCorp Vault. This avoids storing raw sensitive keys in Git repositories.
KMS Integration
- github.com/ondat/trousseau ⭐ 180 [EN CONTENT] [ADVANCED LEVEL] [LEGACY] — Curator Insight: KMS integration designed to encrypt secrets inside etcd using external key management systems. Live Grounding: This repository is unmaintained and archived following Ondat's acquisition. Deprioritized under MVQ rules.
Software Supply Chain
Admission Controllers
- (2022) infoworld.com: Securing the Kubernetes software supply chain with Microsoft's Ratify [EN CONTENT] [ADVANCED LEVEL] 🌟🌟🌟🌟 [ENTERPRISE-STABLE] — Introduces Ratify, an open-source verification engine designed to validate container image signatures and bills of materials (SBOMs) prior to deployment. Curator insight highlights how Ratify integrates as an admission controller with Gatekeeper to block unsigned or non-compliant artifacts. Live grounding confirms that cryptographic signature verification is a cornerstone of modern secure supply chain initiatives.
Threat Landscape (2)
Incident Response
- thenewstack.io: Kubernetes: An Examination of Major Attacks 🌟 [EN CONTENT] [ENTERPRISE-STABLE] — Examines real-world attack vectors and high-profile security incidents targeted at Kubernetes infrastructure, including cryptojacking and dashboard exposure. Curator insight breaks down the progression of an attack from initial access to privilege escalation. Live grounding confirms that threat actors consistently exploit exposed management interfaces and unauthenticated endpoints.
Metrics Security
- (2022) sysdig.com: How attackers use exposed Prometheus server to exploit Kubernetes clusters | Miguel Hernández [EN CONTENT] 🌟🌟🌟🌟 [ENTERPRISE-STABLE] — Dissects a threat scenario presented at KubeCon demonstrating how attackers leverage exposed Prometheus targets to leak cluster topology. Curator insight shows that unauthenticated metrics endpoints frequently leak critical environmental data used to plan secondary exploits. Live grounding warns that proper ingress configurations and token-based authentication are mandatory to secure monitoring setups.
Offensive Security
- tutorialboy24.blogspot.com: A Detailed Talk about K8S Cluster Security from' the Perspective of Attackers (Part 2) 🌟 [EN CONTENT] [ADVANCED LEVEL] [COMMUNITY-TOOL] — Explains tactical cluster hacking methodologies and privilege escalation techniques from an offensive perspective. Curator insight analyzes vectors such as service account token theft and mounting the host socket. Live grounding emphasizes that threat-modeling from an attacker's perspective is vital to proactively designing robust admission and detection rules.
Threat Modeling (1)
Attacking Patterns
- dev.to: A Detailed Talk about K8S Cluster Security from the Perspective' of Attackers (Part 1) [COMMUNITY-TOOL] — A detailed technical review mapping vulnerability configurations from an attacker's point of view. Examines the impact of insecure cluster APIs and excess container rights.
Compliance Auditing (2)
- (2022) sysdig.com: OWASP Kubernetes Top 10 🌟 🌟🌟🌟 [COMMUNITY-TOOL] — Breaks down the OWASP Kubernetes Top 10 architecture from a practical sysadmin viewpoint. Evaluates security boundaries, configurations, and runtime behaviors to mitigate known exploitation routes.
Hardening (3)
- blog.gitguardian.com: Hardening Your Kubernetes Cluster - Threat Model (Pt.' 1) 🌟🌟 [ENTERPRISE-STABLE] — A professional breakdown of modeling security threats across containerized infra. Analyzes the major interfaces and trust boundaries of control systems, nodes, and physical networks.
Tooling
Open Source Security
- mattermost.com: The Top 7 Open Source Tools for Securing Your Kubernetes' Cluster [EN CONTENT] [COMMUNITY-TOOL] — Evaluates seven essential open-source tools for enhancing cluster protection, targeting vulnerability scanning, posture assessment, and threat logs. Curator insight lists classic security aids like Trivy, Falco, and Terrascan. Live grounding shows that combining dynamic runtime checkers with static config linters provides comprehensive coverage across the delivery pipeline.
Vulnerabilities
CVE Case Studies
- empresas.blogthinkbig.com: Descubierta una vulnerabilidad en Kubernetes' que permite acceso a redes restringidas (CVE-2020-8562) [ES CONTENT] [ADVANCED LEVEL] [COMMUNITY-TOOL] — Analiza en detalle la vulnerabilidad de denegación de servicio y elisión de restricciones de red identificada como CVE-2020-8562. El análisis del curador detalla el impacto en la resolución de DNS internas de la API del clúster. La contrastación con el estado actual del sector muestra cómo esta vulnerabilidad impulsó mejoras críticas en los controles de red del plano de control. [SPANISH CONTENT]
Vulnerability Management
CVE Feeds
- kubernetes.io: Announcing the Auto-refreshing Official Kubernetes CVE Feed [COMMUNITY-TOOL] — Official Kubernetes announcement of an auto-refreshing JSON-based CVE feed designed for programmatic security automation. This feed enables automated scanning engines, SIEMs, and cloud-native vulnerability scanners to ingest real-time vulnerability data natively and authoritative definitions straight from the Kubernetes security team.
Vulnerability Scanning
Compliance Auditing (3)
- (2021) blog.flant.com: Kubernetes cluster security assessment with kube-bench and kube-hunter 🌟🌟🌟 [COMMUNITY-TOOL] — Explores proactive vulnerability scanning and automated compliance verification using kube-bench and kube-hunter. Compares their execution models to establish a multi-layered verification strategy inside target clusters.
Interviews
- infoq.com: Armo Releases Kubescape K8s Security Testing Tool: Q&A with VP' Jonathan Kaftzan [COMMUNITY-TOOL] — A developer-focused interview exploring the release of Kubescape. Outlines the technical strategies behind automated cluster auditing and dynamic verification mapping against official security guidelines.
Manifest Auditing (1)
- github.com/Shopify/kubeaudit 🌟🌟 ⭐ 1936 [ENTERPRISE-STABLE] — An open-source auditor that checks active Kubernetes configurations and YAML manifests against real-world security profiles. Prevents misconfigurations such as running containers as root or with excessive privileges.
Workload Security
AWS EKS Hardening
- dev.to/aws-builders: Best Practices for Securing Kubernetes Deployments' 🌟 [EN CONTENT] [ENTERPRISE-STABLE] — Focuses on deployment hardening guidelines tailored for AWS Elastic Kubernetes Service (EKS) and native clusters. Curator insight outlines using IAM Roles for Service Accounts (IRSA) to implement AWS credential isolation. Live grounding confirms that configuring infrastructure-level least-privilege policies prevents lateral cloud infrastructure compromise.
Common Misconfigurations
- fairwinds.com: Discover the Top 5 Kubernetes Security Mistakes You're (Probably)' Making [EN CONTENT] [COMMUNITY-TOOL] — Explores the most common security oversights in Kubernetes cluster deployments, such as running containers as root and missing resource limits. Curator insight matches automated auditing observations, emphasizing the gap between default settings and production requirements. Live grounding highlights that automated policy engines (like Polaris or Kyverno) are essential to systematically mitigate these risks.
Debugging Security
- xenitab.github.io: Kubernetes Ephemeral Container Security 🌟 [EN CONTENT] [ADVANCED LEVEL] [ENTERPRISE-STABLE] — Explains security considerations around the use of ephemeral containers for live cluster troubleshooting. Curator insight warns against exposing node-level namespaces during ad-hoc diagnostics sessions. Live grounding indicates that while ephemeral containers are critical for debugging distroless images, they require strict RBAC policies to prevent escalation.
Deployment Hardening
- armosec.io: How to Secure Deployments in Kubernetes? 🌟 [EN CONTENT] [ENTERPRISE-STABLE] — A practical guide addressing how to configure secure deployments using declarative configurations. Curator insight details defensive parameters such as secrets handling, least-privilege service accounts, and resource controls. Live grounding indicates that automated compliance checks during Deployment creation are vital to prevent misconfigurations from reaching live states.
Developer Best Practices
- dev.to/pavanbelagatti: Kubernetes Security Best Practices For Developers [EN CONTENT] [COMMUNITY-TOOL] — Tailored specifically for application developers to guide secure manifest construction and safe build configurations. Curator insight details practical tips like avoiding hardcoded secrets and keeping image footprints minimal. Live grounding confirms that developer training combined with automated IDE feedback is essential for maintaining secure codebases.
Pod Hardening
- blog.gitguardian.com: Kubernetes Hardening Tutorial Part 1: Pods [EN CONTENT] [COMMUNITY-TOOL] — A granular tutorial guiding developers on how to design and build secure Pod configurations. Curator insight instructs on eliminating default privileges and configuring security contexts. Live grounding shows that implementing Pod Security Standards (PSS) provides a straightforward, out-of-the-box framework to systematically restrict critical container permissions.
- dev.to/thenjdevopsguy: Securing Kubernetes Pods For Production Workloads [EN CONTENT] [ENTERPRISE-STABLE] — A specialized checklist for locking down Pod setups in highly regulated production networks. Curator insight addresses how to enforce non-root execution, limit Capabilities, and bind resource consumption quotas. Live grounding shows that consistent enforcement of these checklists eliminates common container breakout opportunities.
Pod Security Context
- snyk.io: 10 Kubernetes Security Context settings you should understand [EN CONTENT] [ENTERPRISE-STABLE] — A comprehensive guide on utilizing the Kubernetes
securityContextAPI to enforce Pod and container-level boundaries. Curator insight details foundational settings likerunAsNonRoot,readOnlyRootFilesystem, andallowPrivilegeEscalation. Live grounding confirms these configurations remain the primary defense-in-depth mechanisms for preventing container breakouts in 2026 production environments.
💡 Explore Related: Devsecops | Kustomize | Crossplane