Kubernetes security encompasses the practices and controls for protecting container orchestration environments, including cluster hardening, workload isolation, and supply chain integrity.
Critical Kubernetes security risks include misconfigured RBAC allowing privilege escalation, exposed API servers without authentication, vulnerable container images with known CVEs, insecure secrets management storing credentials in plaintext, overly permissive pod security contexts allowing host access, network policies not enforced enabling lateral movement, and supply chain attacks through compromised base images.
RBAC should follow least privilege principles with namespace-scoped roles over cluster-wide roles where possible. Avoid binding cluster-admin to service accounts, implement separate roles for different workload tiers, regularly audit role bindings for excessive permissions, use aggregated ClusterRoles for manageable permission sets, and disable auto-mounting of service account tokens in pods that do not need API access.
Implement Pod Security Standards at the namespace level using restricted profiles that enforce non-root containers, read-only root filesystems, dropped capabilities, and disallowed host namespaces. Use SecurityContexts to set runAsNonRoot, restrict volume types, prevent privilege escalation, and enforce seccomp profiles. OPA Gatekeeper or Kyverno provide policy-as-code for custom admission controls.
Secure the API server by enabling TLS with strong cipher suites, requiring authentication via OIDC or client certificates, implementing admission controllers for policy enforcement, restricting network access to API endpoints, enabling audit logging for all requests, disabling anonymous authentication, using webhook token authentication with identity providers, and regularly rotating service account tokens.
Implement NetworkPolicies to restrict pod-to-pod communication using default-deny ingress and egress rules. Deploy a CNI plugin supporting policy enforcement like Calico or Cilium. Use service mesh for mutual TLS between services, segment namespaces by trust level, restrict external access through ingress controllers with WAF integration, and monitor east-west traffic for anomalous patterns.
Avoid storing secrets as environment variables or ConfigMaps. Use external secret management solutions like HashiCorp Vault, AWS Secrets Manager, or Azure Key Vault with Kubernetes integration through CSI drivers or operator patterns. Enable encryption at rest for etcd, implement RBAC restrictions on secret access, rotate secrets automatically, and audit secret access through API server audit logs.
Use minimal base images like distroless or Alpine, scan images for vulnerabilities in CI/CD pipelines using tools like Trivy or Grype, enforce image signing and verification with Sigstore or Notary, maintain a private registry with access controls, implement admission controllers that reject unsigned or vulnerable images, and regularly rebuild images to incorporate security patches.
Deploy runtime security tools like Falco or Tetragon for syscall monitoring and anomaly detection. Centralize audit logs from API server, container runtime, and node-level sources. Implement alerting for suspicious activities like exec into containers, privileged pod creation, or unusual network connections. Use Kubernetes-native forensics tools for container analysis and maintain incident response runbooks specific to containerized environments.