惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
H
Hackread – Cybersecurity News, Data Breaches, AI and More
V
Vulnerabilities – Threatpost
L
LangChain Blog
Stack Overflow Blog
Stack Overflow Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
云风的 BLOG
云风的 BLOG
C
Cisco Blogs
V
Visual Studio Blog
L
Lohrmann on Cybersecurity
Latest news
Latest news
S
Securelist
The Last Watchdog
The Last Watchdog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
The Register - Security
The Register - Security
Webroot Blog
Webroot Blog
The Cloudflare Blog
S
Secure Thoughts
Y
Y Combinator Blog
aimingoo的专栏
aimingoo的专栏
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
N
News and Events Feed by Topic
S
Security Affairs
Attack and Defense Labs
Attack and Defense Labs
Microsoft Azure Blog
Microsoft Azure Blog
T
Tailwind CSS Blog
V2EX - 技术
V2EX - 技术
GbyAI
GbyAI
L
LINUX DO - 热门话题
PCI Perspectives
PCI Perspectives
Schneier on Security
Schneier on Security
V
V2EX
K
Kaspersky official blog
Hugging Face - Blog
Hugging Face - Blog
AWS News Blog
AWS News Blog
T
The Exploit Database - CXSecurity.com
C
CERT Recently Published Vulnerability Notes
C
Cyber Attacks, Cyber Crime and Cyber Security
P
Proofpoint News Feed
T
Threatpost
WordPress大学
WordPress大学
SecWiki News
SecWiki News
B
Blog RSS Feed
Blog — PlanetScale
Blog — PlanetScale
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
A
Arctic Wolf
酷 壳 – CoolShell
酷 壳 – CoolShell
W
WeLiveSecurity
Jina AI
Jina AI
D
Darknet – Hacking Tools, Hacker News & Cyber Security

Sealos Blog

Build a Full-Stack App with Claude Code + InsForge — Zero Backend Code | Sealos Blog InsForge vs Supabase: Which Backend for AI-Powered Development? | Sealos Blog Kubernetes NodePort Exhaustion: SSH Gateway Solution | Sealos Blog Claude Code Metrics Dashboard: Grafana Setup (2026) | Sealos Blog What Is RustFS? Apache 2.0 MinIO Alternative (2026) | Sealos Blog Claude Code Mobile: iPhone, Android & SSH (2026) | Sealos Blog Eaglercraft Server Hosting: Fast Setup (2026) | Sealos Blog An Honest Review: Migrating a Complex Microservice App from Heroku to Sealos | Sealos Blog The Ultimate Guide to Kubernetes Audit Logging for Security and Compliance | Sealos Blog Cost Optimization Shootout: Sealos Autonomous FinOps vs. Kubecost Manual Reports | Sealos Blog For CTOs: How to Cut Your Cloud Bill by 50% Without Sacrificing Performance | Sealos Blog Building Resilient Systems: A Deep Dive into Sealos High-Availability and Auto-Failover | Sealos Blog Building a Scalable Event-Driven Architecture with Sealos Managed Kafka | Sealos Blog Beyond kubectl apply: 5 GitOps Best Practices for Production-Ready CI/CD on Sealos | Sealos Blog Advanced RAG Pipelines: Why Your Choice of Vector Database (like Milvus) Matters | Sealos Blog Advanced MLOps: How to Monitor and Evaluate LLM Applications in Production | Sealos Blog A Developer's Guide to Kubernetes RBAC: Securing Your Cluster the Easy Way with Sealos | Sealos Blog A CISO's Guide to Cloud Development: Securing the CI/CD Pipeline with Sealos DevBox | Sealos Blog What is Kubernetes Multi-Tenancy? A Guide for Platform Engineers | Sealos Blog What is Infrastructure from Code (IfC)? The Next Step After Infrastructure as Code (IaC) | Sealos Blog What is GitOps? A Beginner's Guide to "Push-to-Deploy" Workflows | Sealos Blog What is eBPF? The Future of Kubernetes Networking and Security | Sealos Blog What is an "AI-Native" Platform? (And Why You Need One for MLOps) | Sealos Blog What is an Agentic Workflow? Building the Next Generation of AI Apps | Sealos Blog What is a Kubernetes Chargeback Model (And How Does it Save You Money?) | Sealos Blog What is a "Headless" Development Environment? (And How it Works with VS Code) | Sealos Blog What is a Graph-Based Vector Database? (And When to Use It Over Milvus) | Sealos Blog What is a "Cloud Operating System"? The Next Evolution of PaaS Explained | Sealos Blog The Real Cost of EKS: How Sealos Delivers a Simpler, Cheaper Kubernetes Experience | Sealos Blog The 3 Types of Kubernetes Autoscaling (HPA, VPA, CA) and How Sealos Manages Them for You | Sealos Blog Sealos vs Vercel: Why a Cloud OS Beats a Frontend Platform for Full-Stack Apps | Sealos Blog Sealos vs. Render vs. Fly.io: A 2025 Guide to the Best Heroku Alternatives | Sealos Blog Sealos vs. OpenShift: Kubernetes for Developers vs. Kubernetes for Ops Teams | Sealos Blog Sealos vs. Netlify: When to Choose a Full Kubernetes Platform over a Static Site Hoster | Sealos Blog Sealos vs. DigitalOcean App Platform: A Head-to-Head Comparison on Cost, Features, and Scalability | Sealos Blog Sealos vs. AWS Elastic Beanstalk: The Modern PaaS for Developers Who Hate YAML | Sealos Blog Sealos DevBox vs. AWS Cloud9: Why Your CDE Should Be Platform-Agnostic | Sealos Blog For Developers: Stop Wasting Time on DevOps. A 10-Minute Guide to Shipping Faster with DevBox. | Sealos Blog Deploying n8n with Docker: From Local Setups to a Radically Simple Cloud Alternative | Sealos Blog The Impact of Prompt Bloat: How the Sealos AI Proxy Can Cache Queries and Cut LLM Costs | Sealos Blog The FinOps Playbook: How to Implement Kubernetes Chargebacks and Showbacks with Sealos | Sealos Blog Smoke Testing for ML Pipelines: Catching Data and Model Errors Before They Hit Production | Sealos Blog Optimizing PostgreSQL Performance: A Guide to Sealos Managed Database Tuning | Sealos Blog Managing Kubernetes Multi-Tenancy: How Sealos Enforces Resource Quotas and Network Policies | Sealos Blog From Days to Minutes: How to Standardize Developer Environments for Your Entire Engineering Org | Sealos Blog For Platform Engineers: How to Build a Golden Path IDP (Internal Developer Platform) with Sealos | Sealos Blog For FinOps Managers: The 5 Leakiest Buckets in Your Kubernetes Budget (And How to Plug Them) | Sealos Blog For Educators & IT Admins: How to Provide a Secure, Scalable Cloud Lab for 1000+ Students on a Budget | Sealos Blog What is a Vector Database? A Beginner's Guide to Milvus, Pinecone, and More | Sealos Blog Why Your Microservices Architecture is Failing (And How a Cloud OS Can Fix It) | Sealos Blog The Power of Autoscaling: A Deep Dive into HPA, VPA, and Cluster Autoscaler | Sealos Blog The Total Economic Impact of Cloud Development Environments (CDEs) | Sealos Blog The Illustrated Guide to the Kubernetes Control Plane | Sealos Blog The MLOps Lifecycle Explained: From Data Prep to Model Deployment | Sealos Blog Beyond Vercel's AI Cloud: The Case for an AI-Native Operating System | Sealos Blog The Architecture of a Modern AI Application: A 2025 Blueprint | Sealos Blog GitHub Codespaces is Great, But Your Workflow is Incomplete. Here's Why. | Sealos Blog The Best Heroku Alternatives in 2025 for Scalability and Cost | Sealos Blog CAST AI vs. Kubecost vs. Sealos: Choosing the Right K8s Cost Management Tool | Sealos Blog DevBox vs. Gitpod vs. Replit: An Unbiased Comparison for 2025 | Sealos Blog Unlocking Hidden Savings: A Guide to Using Spot Instances Safely in Kubernetes | Sealos Blog Can a CDE Really Replace Your MacBook Pro? A Performance Benchmark | Sealos Blog The End of "Works on My Machine": Achieving 100% Reproducible Builds with DevBox | Sealos Blog The Ultimate Guide to GPU Provisioning and Management in Kubernetes | Sealos Blog Rightsizing Kubernetes Workloads: How to Stop Wasting Money on CPU and Memory Requests | Sealos Blog The 2025 Guide to Kubernetes Cost Optimization: 10 Strategies to Cut Your Bill in Half | Sealos Blog FinOps for Startups: How to Build a Cost-Conscious Culture from Day One | Sealos Blog How to Onboard a New Developer in Under 5 Minutes with Sealos DevBox | Sealos Blog Calculating Kubernetes Costs: A Breakdown of EKS, GKE, and AKS Pricing Models | Sealos Blog Case Study: How We Reduced Our Kubernetes Bill by 87% with Sealos | Sealos Blog Are You Overpaying for Managed Kubernetes? The True Cost of Vendor Lock-in | Sealos Blog Beyond Monitoring: How Sealos Autonomously Optimizes Your Cloud Spend | Sealos Blog A Secure-by-Design Development Workflow with Isolated Cloud Environments | Sealos Blog Setting Up a Collaborative Python Data Science Environment with DevBox | Sealos Blog Using the Sealos AI Proxy to Manage and Cache LLM API Calls | Sealos Blog Migration Guide: Moving Your Node.js & Postgres App from Heroku to Sealos in Under an Hour | Sealos Blog Serving Machine Learning Models at Scale: A Guide to Inference Optimization | Sealos Blog Headless Development with Sealos: Using Your Local VS Code with a Powerful Cloud Backend | Sealos Blog How to Build and Deploy a RAG Pipeline with Llama 3 and Milvus on Sealos | Sealos Blog From Localhost to Production in 15 Minutes: A Full-Stack CDE Workflow with Sealos DevBox | Sealos Blog GitOps on Autopilot: Implementing a CI/CD Pipeline with Sealos and GitHub Actions | Sealos Blog Fine-Tuning Open-Source LLMs on a Budget with Sealos | Sealos Blog From Docker Compose to Kubernetes: A Simple Migration Path with Sealos | Sealos Blog Building an AI Agentic Workflow with LangChain and Sealos | Sealos Blog What is Helm for Kubernetes? The Ultimate Package Manager Explained | Sealos Blog What is a Custom Resource Definition (CRD) in Kubernetes? | Sealos Blog What is a Kubernetes StatefulSet? A Practical Guide | Sealos Blog What is a Kubernetes Ingress Controller? A Guide to Smart Traffic Routing | Sealos Blog What is a Kubernetes Operator? Automating Complex Applications | Sealos Blog What is a Kubernetes Service? A Simple Guide for Developers | Sealos Blog Streamlining Your CI/CD Pipeline with a DevBox Build Environment | Sealos Blog Why Standardized Development Environments Are Key to Team Velocity | Sealos Blog What Is GitHub Codespace? | Sealos Blog DevBox Install? Skip It Entirely. Get a Ready-to-Code Environment in One Click with Sealos DevBox. | Sealos Blog How to Set Up a DevBox: The Ultimate Guide to 1-Click Cloud Development | Sealos Blog Empowering Indie Devs and Startup Teams: How Sealos DevBox Accelerates Agile Development | Sealos Blog From Chaos to Consistency: How Sealos DevBox Transforms Enterprise Development Workflows | Sealos Blog From Campus Labs to Cloud Freedom: How Sealos DevBox Supercharges Student Development | Sealos Blog How Sealos DevBox Cut Container Commit Time from 15 Minutes to 1 Second | Sealos Blog DevBox vs Codespaces: Which Remote Dev Environment Fits You Best? | Sealos Blog
A Practical Guide to Kubernetes Security: Hardening Your Cluster in 2025 | Sealos Blog
Sealos · 2025-09-07 · via Sealos Blog

Kubernetes won the container orchestration wars by making distributed systems feel manageable. But with great power comes a large attack surface. Misconfigurations, over‑privileged workloads, weak boundaries, and insecure defaults can turn your cluster into a liability. The good news: most risks are predictable and defendable with disciplined practices and a few modern tools.

This practical guide walks you through what Kubernetes security is, why it matters, how the security model works, and how to harden your clusters in 2025 with hands‑on examples you can apply today.


Kubernetes security is the practice of protecting a Kubernetes environment across its lifecycle: from the supply chain that builds container images, to the control plane and data plane that run workloads, to the runtime behavior of applications and the boundaries between them.

Key layers you must secure:

  • Supply chain: source code, dependencies, container images, signatures, SBOMs.
  • Control plane: API server, etcd, controller manager, scheduler.
  • Data plane: nodes, kubelet, CNI, container runtime.
  • Workloads: pods, deployments, sidecars, secrets.
  • Access: authentication (AuthN), authorization (AuthZ), admission control.
  • Network: policies, ingress/egress, service mesh, TLS/mTLS.
  • Observability: audit logs, runtime detection, forensics, backups.

Kubernetes is not “secure by default.” Its power is its flexibility; your job is to install guardrails and enforce least privilege.


  • Rising complexity: multi‑cluster, multi‑cloud, and edge deployments expand the attack surface.
  • Supply chain threats: dependency hijacking, typosquatting, and poisoned images remain common.
  • Identity shifts left: service identities (not users) drive access; misbinding identities can expose data.
  • Regulatory pressure: SOC 2, ISO 27001, PCI, HIPAA require controls and evidence.
  • Evolving Kubernetes: features like Pod Security Admission and policy engines have matured; attackers know them too.

Security is now a continuous program, not a one‑time setup.


  • Authentication: Users, service accounts, and nodes authenticate via certificates, tokens, OIDC.
  • Authorization: RBAC (role‑based access control) determines what identities can do.
  • Admission control: Policies validate or mutate resources before they persist (e.g., Pod Security Admission, ValidatingAdmissionPolicy, Kyverno).
  • Runtime isolation: Linux primitives (namespaces, cgroups, seccomp, AppArmor/SELinux) and container runtimes isolate processes.
  • Network segmentation: CNI plugins and NetworkPolicies control pod‑to‑pod and pod‑to‑external traffic.
  • Data protection: etcd encryption at rest; TLS in transit; secret management integrations.
  • Observability and audit: API audit logs, runtime detection (e.g., Falco), and metrics create feedback loops.

With that mental model, let’s harden a real cluster.


Before turning knobs, define a threat model:

  • Who are the actors? Developers, CI/CD systems, cluster admins, tenants, attackers.
  • What are assets? API server, credentials, secrets, workloads, data stores.
  • What are risks? Privilege escalation, lateral movement, data exfiltration, persistence.

Guiding principles:

  • Least privilege everywhere (humans and workloads).
  • Secure by default (deny by default, explicit allow).
  • Verified supply chain (signed, scanned, attested).
  • Defense in depth (multiple, independent controls).
  • Immutable infrastructure (reconcile drift, audit changes).
  • Evidence‑based (logs and metrics you can prove).

The control plane is the brain. Protect it like production databases: limited access, strong auth, encryption, and monitoring.

API Server Basics

  • Require TLS v1.2+ for all connections.
  • Disable anonymous auth.
  • Enforce RBAC.
  • Turn on audit logging.
  • Encrypt secrets at rest in etcd.

Example kube‑apiserver flags (managed control planes expose these as settings rather than flags):

Audit policy example (log sensitive writes, decline noisy reads):

Secrets encryption at rest (also supported in managed services):

Enable with the --encryption-provider-config flag and rotate keys regularly.

etcd Security

  • Use TLS client and peer certs; restrict access to control plane only.
  • Enable disk encryption on nodes hosting etcd.
  • Regular backups with encryption and offsite storage.
  • Network segmentation: etcd should not be Internet‑reachable.

Attackers often jump from a container to the node. Reduce blast radius.

Kubelet Configuration

  • Disable unauthenticated access; disable read‑only port (10255).
  • Use webhook authz/authn.
  • Enforce TLS v1.2+.
  • Enable seccomp default profile when supported by your version.

Start kubelet with:

Host OS and Runtime

  • Use minimal, auto‑updating OS (e.g., Bottlerocket, Flatcar, COS).
  • Keep kernel and container runtime (containerd, CRI‑O) patched.
  • Limit SSH (ideally disable, manage via SSM/OSLogin); enforce MFA for break‑glass.
  • SELinux/AppArmor enforcing; disable unnecessary kernel modules.
  • Consider sandboxed runtimes for untrusted workloads (gVisor, Kata Containers) via RuntimeClass.

RuntimeClass example:

Use in a Pod:


RBAC mistakes are common. Start with deny by default.

  • Disable legacy ABAC if present.
  • Prefer Roles/RoleBindings scoped to namespaces; reserve ClusterRoles for cluster‑wide resources.
  • Bind service accounts explicitly; avoid default service account access in namespaces.

Example least‑privilege Role and RoleBinding:

Best practices:

  • Turn off auto‑mounting tokens when not needed: set automountServiceAccountToken: false on Pods or ServiceAccounts.
  • Use short‑lived, projected service account tokens (TokenRequest API) and cloud‑native workload identity for cloud APIs (e.g., EKS IRSA, GKE Workload Identity, AKS Managed Identities).

Admission controllers enforce security before resources are persisted.

Pod Security Admission (PSA)

Pod Security Policy is removed; use Pod Security Admission via namespace labels.

  • Levels: privileged, baseline, restricted.
  • Enforce restricted wherever possible.

Apply restricted to a namespace:

ValidatingAdmissionPolicy (CEL)

Recent Kubernetes releases support policy enforcement with CEL expressions without webhooks. Example: require allowPrivilegeEscalation: false.

Bind it:

Policy Engines (Kyverno/Gatekeeper)

For richer policies and supply chain verification, use:

  • Kyverno: Kubernetes‑native, policy‑as‑YAML; supports image signature verification.
  • OPA Gatekeeper: Rego‑based, very flexible.

Kyverno example to verify container image signatures (Sigstore Cosign):


Namespaces are your first tenancy boundary.

  • Assign each team/app its own namespace.
  • Apply PSA labels per namespace.
  • Use ResourceQuotas and LimitRanges to prevent noisy neighbor issues.
  • Use NetworkPolicies to isolate traffic across namespaces.
  • Optionally, pin tenants to dedicated nodes with taints/tolerations and nodeSelectors.

Example resource limits:


Most incidents start with a vulnerable or misconfigured pod. Lock them down.

Checklist for Pod spec:

  • Run as non‑root.
  • Drop Linux capabilities; add only what you need.
  • Read‑only root filesystem.
  • No privilege escalation.
  • Seccomp profile set to RuntimeDefault or custom.
  • AppArmor/SELinux profiles enforced.
  • Limit resources (CPU/memory) to curb DoS.
  • Avoid hostPath volumes; if needed, read‑only and narrow paths.
  • Disable hostNetwork, hostPID, hostIPC unless absolutely necessary.

Secure Pod example:

Prefer distroless or minimal images, pin versions with digests, and avoid shell and package managers in production images.


Without NetworkPolicies, most CNIs allow all pod‑to‑pod traffic. That’s lateral‑movement heaven.

  1. Default deny egress/ingress in each namespace:
  1. Allow only what’s needed. For example, web pods can talk to db pods on 5432:

Advanced:

  • Use CNIs like Cilium or Calico for robust policy features; Cilium can enforce L7 policies and visibility.
  • Egress control with FQDN policies and DNS restrictions to prevent data exfiltration.

  • Terminate TLS for all external endpoints; use cert‑manager to automate certificates.

cert‑manager example:

Ingress with TLS:

  • Use a service mesh (e.g., Istio, Linkerd) to enable mTLS by default and apply zero‑trust policies.

Istio mTLS enforcement:


Kubernetes Secrets are base64‑encoded by default. Treat them as sensitive.

  • Enable encryption at rest (control plane section).
  • Restrict RBAC to secrets; avoid listing secrets broadly.
  • Avoid putting secrets in env vars when possible; prefer volumes to reduce accidental logs exposure.
  • Rotate secrets and tokens regularly.

External secret stores:

  • Use CSI Secrets Store with providers for AWS/GCP/Azure/Vault.
  • Map cloud IAM roles to service accounts for least privilege.

Example: CSI Secret Store + external Vault secret:

Ensure token projection and workload identity mapping are correctly configured.


Prevent compromised images from ever reaching the cluster.

  • Build provenance: generate SBOMs (e.g., Syft), sign artifacts (Sigstore Cosign), record attestations (SLSA‑aligned).
  • Scan images for vulnerabilities (Trivy, Grype) in CI and registries; fail builds on critical CVEs with available fixes.
  • Pin images by digest in manifests; avoid floating tags (latest).
  • Enforce signature verification at admission (Kyverno or ValidatingAdmissionPolicy + image verification tools).
  • Restrict registries: only allow images from approved registries.

Cosign signing:

Kyverno deny non‑approved registries:


Detect and respond to suspicious behavior.

  • Enable API audit logs and ship to a SIEM.
  • Collect container and node metrics/logs (Prometheus, Loki, CloudWatch/Stackdriver).
  • Runtime detection tools (Falco, Cilium Tetragon) to alert on abnormal syscalls (e.g., opening /etc/shadow).
  • Set resource limits to mitigate noisy neighbor / fork bombs.
  • Prepare for forensics: centralized logs, immutable buckets, and node image snapshots (where possible).

Falco example rule snippet:


0–30 Days: Baseline Controls

  • Enforce RBAC; remove wildcard permissions.
  • Disable anonymous auth on API server and kubelet; enable audit logs.
  • Turn on encryption at rest for secrets.
  • Label namespaces with Pod Security Admission: enforce restricted where possible.
  • Apply default‑deny NetworkPolicies in all namespaces.
  • Harden workloads: runAsNonRoot, drop capabilities, readOnlyRootFilesystem.
  • Rotate and pin image tags by digest; scan images in CI.
  • Enable TLS for all ingress; deploy cert‑manager.
  • Centralize logs and alerts; basic Falco/Tetragon ruleset.

31–60 Days: Policy and Identity

  • Adopt Kyverno or Gatekeeper; codify key policies (no privileged pods, registry allowlist, resource limits, image signatures).
  • Introduce ValidatingAdmissionPolicy for simple CEL based constraints.
  • Integrate workload identity: IRSA (EKS), Workload Identity (GKE), Managed Identity (AKS).
  • Introduce a service mesh for mTLS between services (start with critical namespaces).
  • Set up CSI Secrets Store with cloud KMS or Vault.

61–90 Days: Advanced Isolation and Resilience

  • Segment tenants with namespaces, quotas, and dedicated nodes (taints/tolerations).
  • Adopt sandboxed runtime (gVisor/Kata) for untrusted or multi‑tenant workloads.
  • Implement egress control and DNS restrictions.
  • Back up etcd and critical resources; practice restore.
  • Build provenance (SBOMs, signatures, attestations) into CI/CD and admission.
  • Add periodic security tests: kube‑bench (CIS), kube‑hunter (network), KubeLinter (manifests).

  • EKS: Use IRSA for IAM roles; restrict security group rules; enable control plane logging; use AWS KMS for secret encryption.
  • GKE: Use Workload Identity; private clusters; shielded nodes; Binary Authorization for image attestation.
  • AKS: Use Managed Identities; Azure Policy for Kubernetes (built on Gatekeeper); private clusters and Azure Key Vault provider.

Across clouds:

  • Prefer private control planes and nodes; use VPN/peering.
  • Control egress with NAT gateways and firewall rules.
  • Lock registry access to your VPC/VNet and enable content trust.

  • Scanning: Trivy, Grype, Syft (SBOM).
  • Policy: Kyverno, OPA Gatekeeper, ValidatingAdmissionPolicy (CEL).
  • Runtime: Falco, Tetragon.
  • Benchmarks: kube‑bench (CIS), kube‑hunter.
  • Supply chain: Sigstore Cosign, Rekor, SLSA framework.
  • Hardening guides: CIS Kubernetes Benchmark; vendor hardening docs.

  • Relying on network perimeters only; ignoring pod‑level segmentation.
  • Granting cluster‑admin to CI/CD or developers “temporarily” and never revoking.
  • Using latest image tags; skipping digest pinning and signature verification.
  • Mounting hostPath volumes broadly or running with hostNetwork without need.
  • Treating secrets as non‑sensitive; leaving them in env vars or repos.
  • Forgetting the kubelet: leaving read‑only port enabled or anonymous auth on.
  • Assuming managed clusters are “secure enough” without your policies.

  • API server: RBAC only, anonymous off, audit on, secrets encrypted at rest.
  • etcd: TLS, restricted network, regular encrypted backups.
  • Kubelet: anonymous off, webhook authz, read‑only port 0, TLS v1.2+, SeccompDefault.
  • Namespaces: PSA labels set; quotas and default limits.
  • Workloads: non‑root, no privilege escalation, read‑only FS, caps dropped, seccomp/AppArmor.
  • Network: default‑deny policies; explicit allow rules; egress/DNS controls.
  • Ingress: TLS everywhere; cert‑manager automation; HSTS at edge.
  • Identity: short‑lived tokens; workload identity for cloud APIs; no default SA tokens.
  • Supply chain: scan, sign, attest; registry allowlist; digest pinning; admission verification.
  • Observability: audit logs to SIEM; runtime detection; alerting runbooks.
  • DR: etcd and config backups; tested restore procedure.

Kubernetes security in 2025 is about layering practical, automatable controls across the entire lifecycle. Start by locking down the control plane and kubelet, enforce least privilege with RBAC, and turn on Pod Security Admission. Segment the network with default‑deny policies and mTLS, and harden pods with strong security contexts. Shift left with signed, scanned images and admission policies that block unsafe deployments. Finally, instrument everything: audit logs, runtime detection, and tested backups.

Security isn’t a destination; it’s a continuous feedback loop. With the guardrails in this guide—plus a bias for least privilege and verification—you can run Kubernetes with confidence and reduce the blast radius when incidents occur. Take the 90‑day plan, adapt it to your environment, and make security part of your platform’s DNA.