Home / Kubernetes / Security
Kubernetes guide

Kubernetes security

Out of the box, Kubernetes is permissive: containers can run as root and any pod can reach any other. A handful of controls, applied consistently from templates, closes most of the gaps. Keeping clusters upgraded closes most of the rest.

DefaultDeny, then allow
ImagesScanned and signed
PoliciesEnforced at admission
UpgradesEvery few months

The controls that matter most

ControlWhat it doesCommon choices
Access control (RBAC)People and systems get only the permissions they needGroups from your identity provider, no shared admin accounts
Namespaces and quotasTeams are separated and cannot use up the whole clusterOne namespace per team and environment
Network policiesPods can only talk to what they need toDefault-deny, with Cilium or Calico
Pod securityBlocks root containers and risky settingsPod Security Standards at the restricted level
Image securityOnly trusted, scanned images runTrivy scanning, cosign signatures, a private registry
Policy engineEnforces your rules when anything is createdKyverno or OPA Gatekeeper
SecretsKeeps passwords and keys out of Git and imagesVault or cloud secret stores via External Secrets
Audit and runtimeRecords changes and spots suspicious behaviourAPI audit logs, Falco
BenchmarksChecks clusters against known good settingsCIS Kubernetes Benchmark with kube-bench

Keeping clusters upgraded

  • Kubernetes ships about three minor versions a year, and each is supported for roughly fourteen months.
  • Clusters more than a couple of versions behind become hard to upgrade and lose security fixes.
  • Upgrade on a schedule: non-production first, a short soak, then production. Practise it, so it becomes routine.
  • Track deprecated APIs in your manifests before each upgrade, so applications do not break.

Planning a Kubernetes platform, or fixing one?

Tell us how many applications and teams you have, how you deploy today and where it should run. We will come back with an honest view: whether Kubernetes fits, what a lean platform looks like, and what it takes to run.