Kubernetes Security & Hardening
Production-hardened, identity-integrated clusters. Starts with the PKI that holds Kubernetes together, adds human login through OIDC/SSO/MFA, secures traffic at the edge and inside the cluster, and ends with a hardened cluster built from scratch and checked against CIS.
What you'll be able to do
- Map every certificate in a cluster, and rotate them without an outage
- Put OIDC login (Keycloak/Dex + kubelogin) with MFA in front of kubectl
- Terminate and pass through TLS/mTLS with Ingress and the Gateway API
- Enforce policy and verify supply chain with admission control
Before you start
Kubernetes Administration Level 2, TLS basics.
How it works
Each lesson: plain-language idea → how it really works → hands-on. Each section ends with a cheat sheet & self-check.
Curriculum
Lessons marked “Read” are ready; the rest are on the way.
Identity & Access
- 01Cluster PKI & certificatesCluster CA, kubelet serving/client certs, rotation, expiryRead →
- 02cert-manager in productionIssuers, ACME, private CA, renewal monitoringRead →
- 03Authentication methodsX.509, service account tokens, webhook, OIDCRead →
- 04OIDC login for kubectlKeycloak or Dex, kubelogin, group claimsRead →
- 05SSO, federation & MFAEnterprise IdP, TOTP/MFA, break-glass accessRead →
- 06RBAC design at scalePersonas, aggregation, auditing who can do whatRead →
- 📋Cheat sheet & self-checkEvery command from this section on one page, then 19 questions to check yourself.Open →
Traffic Security
- 07Ingress controllers & TLSNGINX/Traefik, termination vs passthroughRead →
- 08Gateway APIGatewayClass, HTTPRoute, cross-namespace policyRead →
- 09Network policies & mTLSDefault-deny, Cilium/Calico policy, workload mTLSRead →
- 📋Cheat sheet & self-checkEvery command from this section on one page, then 9 questions to check yourself.Open →
Workload & Supply Chain
- 10Pod Security & admission controlPSA levels, Kyverno/Gatekeeper policiesRead →
- 11Secrets managementEncryption at rest, KMS, External Secrets, VaultRead →
- 12Supply chain securityImage signing (cosign), SBOM, scanning, admission verifyRead →
- 📋Cheat sheet & self-checkEvery command from this section on one page, then 9 questions to check yourself.Open →
Detect & Harden
- 13Audit logging & runtime detectionAudit policy design, FalcoRead →
- 14CIS benchmark hardeningkube-bench, node hardening, SELinuxRead →
- 15Capstone: hardened cluster from scratchBuild it, attack it, write the runbookRead →
- 📋Cheat sheet & self-checkEvery command from this section on one page, then 8 questions to check yourself.Open →
Real-world scenarios
Work through each one: symptom → misleading signal → evidence → root cause → prevention.
Every kubelet certificate was issued on the same day. Plan the rotation before it becomes an outage.
Trust bundles, leaf certificates and rotation order.
What signing proves, and what it doesn't.
This site is a public version of my personal engineering knowledge hub. It intentionally excludes confidential company information and internal operational details.