Securing a Kubernetes cluster is not optional at production scale. A misconfigured RBAC policy, an over-privileged ServiceAccount, or a container running as root can expose your entire cluster to attackers. This pillar covers the security controls that engineering teams at Razorpay, Zerodha, and PhonePe use to harden their Kubernetes workloads in production.
What This Pillar Covers
- Role-Based Access Control (RBAC) with Roles, ClusterRoles, and ServiceAccounts
- Pod Security Standards — Privileged, Baseline, and Restricted enforcement levels
- securityContext settings — runAsNonRoot, readOnlyRootFilesystem, capability dropping
- Managing Kubernetes Secrets with Vault and ConfigMaps
- Network Policies for pod-level traffic isolation
- Admission controllers and policy enforcement
Who This Is For
DevOps engineers, platform engineers, and security engineers responsible for hardening Kubernetes clusters, enforcing least-privilege access, and meeting compliance requirements in production environments.