A tool to determine restrictive level for Kubernetes workloads
-
Updated
Jun 1, 2023 - Go
A tool to determine restrictive level for Kubernetes workloads
Kubernetes Pod Security Standards implemented using Kubernetes Validating Admission Policies. Support of Enforce Baseline and Restricted profiles natively with configurable policy exclusions.
Kubernetes CKS practice scenarios and hands-on security labs for Certified Kubernetes Security Specialist exam prep. Free sample includes CIS hardening and control plane security scenarios. Full premium guide with advanced runtime, RBAC, Falco and zero-trust labs available.
12 hands-on CKS labs covering API server hardening, audit logs, NetworkPolicy, ingress security, RBAC, service accounts, Pod Security, admission control, node and kubelet hardening, seccomp, AppArmor, secure pod design, secrets, image scanning, SBOMs, signing, manifest analysis, Falco, runtime security, and timed readiness.
Chaosify is a Kubernetes security testing CLI that proves your admission controls, RBAC policies, network segmentation, and runtime detection actually work by running targeted tests against a live cluster and producing structured evidence.
Kubernetes security posture scanner — audits manifests and live clusters for misconfigurations against CIS Benchmarks, Pod Security Standards, and the NSA/CISA hardening guide, with SARIF output and remediation guidance.
Real-time Kubernetes pod security monitoring and enforcement: dashboard, Helm, Gatekeeper, Pod Security Admission.
Multi-environment Kubernetes platform (staging/prod) built with Kustomize and a GitHub Actions pipeline, hardened with a defense-in-depth DevSecOps setup.
Kubernetes Security Auditor — 23 CIS-based checks for RBAC, pod security, secrets, network policies, resource limits, and image security. CLI with HTML/JSON reports.
Production-grade Kubernetes security lab with 5 attack scenarios, automated detection (Trivy/Falco/Kubescape), and hands-on exploitation
Production-inspired Kubernetes security practices covering RBAC, Network Policies, Pod Security Standards, admission control, secrets management, runtime security, and policy enforcement.
End-to-end DevSecOps hardening of a PCI-scoped payments microservice: workload hardening, a signing CI/CD supply chain, Istio zero-trust mTLS, and an offensive pen-test that maps findings back to the defences. All four tasks verified at runtime on a local k3d cluster.
Audit Kubernetes workload manifests against the Pod Security Standards. Flags privileged containers, host namespaces, hostPath mounts, dangerous capabilities, runAsRoot, missing seccomp, missing resource limits/probes, default ServiceAccount with token automount. Library + CLI.
Secure multi-tenant Kubernetes platform with RBAC, Cilium network isolation, Pod Security, TLS, GitOps and observability.
Validating/mutating admission webhook in Rust (kube-rs) - pod security, mTLS injection, policy-as-code for zero-trust K8s
Production-grade Kubernetes security
Kubernetes operator for SLO enforcement, pod security guardrails, and automated namespace lifecycle management.
Kyverno policy engine setup for a k3s cluster that is security compliant.
Kubernetes reference for sandboxed automated agent workloads with egress controls, Vault integration patterns, and PII redaction.
Shell-based Kubernetes security audits for RBAC and workload posture (PSA, capabilities, cloud identity). Vanilla, EKS, GKE, AKS & OpenShift. Optional Terraform lab stacks.
Add a description, image, and links to the pod-security topic page so that developers can more easily learn about it.
To associate your repository with the pod-security topic, visit your repo's landing page and select "manage topics."