K8S Security Policies

Applies namespace Pod Security Standards, default-deny NetworkPolicy, least-privilege RBAC, Gatekeeper/Kyverno admission, and optional Istio STRICT mTLS on Kubernetes. Use when the work is network segmentation, pod hardening, or CIS/NIST control mapping. Not for Docker Compose, Swarm, or Nomad; not a generic app-manifest deploy chair.

Kayforkind Updated

File contents

Kayforkind/skill-slice commit 938e381571

Frequently asked questions

npx skillmds@latest add kayforkind/k8s-security-policies