Kubernetes
Kubernetes & Container Security Checklist
A cluster-hardening checklist for RBAC, supply chain, runtime, network policies, and secrets.
- Estimated time
- 4–12 Weeks
- Audience
- Platform, SRE, and Cloud Security Teams
- Last updated
Operational reference for Kubernetes security. Aligns with CIS Kubernetes Benchmarks; not a CNCF certification of your cluster.
Progress is saved in this browser only. Nothing is sent to a server.
Phase 1: Cluster Baseline
Phase 2: Workload Hygiene
Phase 3: Supply Chain
Phase 4: Runtime & Secrets
FAQ
CIS Benchmark vs NSA/CISA K8s hardening?+–
Both are useful. CIS is a scored benchmark many auditors recognize.
Does this replace AppSec?+–
No. Misconfigured RBAC plus an app RCE is still a cluster-takeover path.
Managed K8s (EKS/GKE/AKS)?+–
The provider covers the control plane; you still own IAM, workloads, and many data-plane settings.
Is service mesh required?+–
No. It can help mTLS. Start with RBAC, PSA, and network policies.
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer