K8S Network And Identity Policy

Use when authoring or hardening the Kubernetes network and workload-identity policy for a service after security and infrastructure-platform have decided the trust zones, identity model, and east-west posture. Produces default-deny NetworkPolicy (namespace-scoped, label-selected), least-privilege ServiceAccount + Role/ClusterRole bindings, Ingress / Gateway API exposure posture, mTLS or service-mesh wiring where adopted, image-pull secret and registry-auth handling, and Pod Security Standards namespace enforcement. Do not use for workload manifest authoring, autoscaling and resilience topology, observability wiring, image hardening / signing / admission-controller policy, or cluster provisioning; use the other Family G archetype skills (cluster provisioning is out of family).

aibot88 Updated 3 repo stars

File contents

aibot88/sec_skill_store/tree/main/skills/claudskills/k8s-network-and-identity-policy commit bc9f42c550

Frequently asked questions

npx skillmds@latest add aibot88/k8s-network-and-identity-policy