Kubernetes Security: RBAC, Policies, and Secrets
Learn to secure Kubernetes with least-privilege RBAC, Pod Security Standards, network policies, encrypted secrets, and runtime alerts on a local cluster.
What You'll Learn
Understanding the Kubernetes Attack Surface
The cluster that fell to one forgotten token A team at acme-shop runs an internal admin dashboard on Kubernetes.
Granting Least Privilege with RBAC
How RBAC objects fit together RBAC (role-based access control) decides who can do what in the cluster.
Hardening Service Accounts and Tokens
How pods authenticate with service accounts A service account is the identity a pod uses to call the Kubernetes API.
Enforcing Pod Security Standards
The three levels Pod Security Standards define three profiles for pod settings, and Pod Security Admission enforces them through namespace labels.
Restricting Traffic with Network Policies
Why policies need an enforcing network plugin By default every pod can talk to every other pod.
Encrypting Secrets at Rest
Why base64 is not protection Kubernetes Secrets are stored base64-encoded, which is a reversible encoding and not encryption.
Skills You'll Master
Curriculum Index11 topics
Understanding the Kubernetes Attack Surface
The cluster that fell to one forgotten token A team at acme-shop runs an internal admin dashboard on Kubernetes.
Granting Least Privilege with RBAC
How RBAC objects fit together RBAC (role-based access control) decides who can do what in the cluster.
Hardening Service Accounts and Tokens
How pods authenticate with service accounts A service account is the identity a pod uses to call the Kubernetes API.
Enforcing Pod Security Standards
The three levels Pod Security Standards define three profiles for pod settings, and Pod Security Admission enforces...
Restricting Traffic with Network Policies
Why policies need an enforcing network plugin By default every pod can talk to every other pod.
Encrypting Secrets at Rest
Why base64 is not protection Kubernetes Secrets are stored base64-encoded, which is a reversible encoding and not...
Protecting etcd and the Control Plane
What etcd holds and who can reach it etcd stores every object in the cluster, including Secrets, ConfigMaps, and RBAC...
Enforcing Policies at Admission
What admission controllers do After a request is authenticated and authorised, admission controllers can validate or...
Detecting Runtime Threats with Falco
What Falco watches Everything so far prevents problems.
Hands-on Lab: Audit and Harden a Local Cluster
Before you start You need Docker, kind, and kubectl installed.
Quick Reference and Common Mistakes
Quick reference Common mistakes Granting cluster-admin to a workload is the classic shortcut, and it makes any pod...
Career Impact
Roles that use the skills in this module.
- High Demand
DevSecOps Engineer
₹12L - ₹30L a year
- Growing
Platform Engineer
₹15L - ₹28L a year
- High Demand
Site Reliability Engineer
₹12L - ₹28L a year
Next Modules
Practice on the Coding Sheet
Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.
Open the Coding SheetFrequently Asked Questions
Not in the cluster itself. Secrets are base64-encoded, which is an encoding and not encryption, and they are stored in etcd. Self-managed clusters need encryption at rest configured on the API server, while managed services such as EKS, GKE, and AKS handle storage encryption in provider settings.
No. A NetworkPolicy object is accepted by the API on any cluster, but it is enforced only if the network plugin supports it, such as Calico or Cilium. Without an enforcing plugin, a default-deny policy appears to apply while blocking nothing.
Pod Security Admission, which enforces the three Pod Security Standards (privileged, baseline, restricted) through namespace labels. PodSecurityPolicy was removed in Kubernetes 1.25.
The default account is shared by every pod in the namespace that does not name another one, so any permission you grant it reaches all of them. Give each workload its own service account with only the permissions it needs, and disable token mounting where the pod never calls the API.