Kubernetes guide
Kubernetes security
Out of the box, Kubernetes is permissive: containers can run as root and any pod can reach any other. A handful of controls, applied consistently from templates, closes most of the gaps. Keeping clusters upgraded closes most of the rest.
DefaultDeny, then allow
ImagesScanned and signed
PoliciesEnforced at admission
UpgradesEvery few months
The controls that matter most
| Control | What it does | Common choices |
|---|---|---|
| Access control (RBAC) | People and systems get only the permissions they need | Groups from your identity provider, no shared admin accounts |
| Namespaces and quotas | Teams are separated and cannot use up the whole cluster | One namespace per team and environment |
| Network policies | Pods can only talk to what they need to | Default-deny, with Cilium or Calico |
| Pod security | Blocks root containers and risky settings | Pod Security Standards at the restricted level |
| Image security | Only trusted, scanned images run | Trivy scanning, cosign signatures, a private registry |
| Policy engine | Enforces your rules when anything is created | Kyverno or OPA Gatekeeper |
| Secrets | Keeps passwords and keys out of Git and images | Vault or cloud secret stores via External Secrets |
| Audit and runtime | Records changes and spots suspicious behaviour | API audit logs, Falco |
| Benchmarks | Checks clusters against known good settings | CIS Kubernetes Benchmark with kube-bench |
Keeping clusters upgraded
- Kubernetes ships about three minor versions a year, and each is supported for roughly fourteen months.
- Clusters more than a couple of versions behind become hard to upgrade and lose security fixes.
- Upgrade on a schedule: non-production first, a short soak, then production. Practise it, so it becomes routine.
- Track deprecated APIs in your manifests before each upgrade, so applications do not break.
More Kubernetes guides: Platform design · GitOps delivery · Multi-cluster and on-prem · Kubernetes FAQ · Use case: festive-season scale
Planning a Kubernetes platform, or fixing one?
Tell us how many applications and teams you have, how you deploy today and where it should run. We will come back with an honest view: whether Kubernetes fits, what a lean platform looks like, and what it takes to run.