A comprehensive hands-on guide to hardening Kubernetes clusters across three security layers. Starts with running kube-bench to establish a CIS Benchmark baseline on a fresh kind cluster, then walks through building least-privilege RBAC policies for a CI pipeline service account, auditing existing permissions with rakkess and
Table of contents
PrerequisitesTable of ContentsThe Kubernetes Threat LandscapeWhat You'll BuildDemo 1: Run a Cluster Security Baseline with kube-benchHow to Configure RBACDemo 2 – Build a Least-Privilege RBAC Policy for a CI PipelineDemo 3 – Audit RBAC with rakkess and rbac-lookupHow to Harden Pod Runtime SecurityDemo 4 – Harden a Pod with securityContextDemo 5 – Deploy Falco and Write a Custom Detection RuleCleanupConclusionSort: