Defending Kubernetes

Harden and monitor a Kubernetes cluster against the attacks that actually happen — RBAC least privilege and escalation paths, Pod Security Admission enforcement, network policy default-deny, secrets and service-account token exposure, control-plane and kubelet exposure, and audit-log-based detection. Use when reviewing a cluster's security posture, responding to a suspected cluster compromise, deciding what to enforce and detect, or translating an attack path from attacking-eks-gke-aks into a defense.

trilwu 10b1a17 8.7 KB Updated

File contents

trilwu/secskills/tree/main/secskills-defense/skills/defending-kubernetes commit 10b1a17f54

Frequently asked questions

npx skillmds add trilwu/defending-kubernetes