Skip to main content

Kubernetes Security: RBAC, Policies, and Secrets

Learn to secure Kubernetes with least-privilege RBAC, Pod Security Standards, network policies, encrypted secrets, and runtime alerts on a local cluster.

~3.5 hours
11 Topics
Hands-on Scenarios

What You'll Learn

Understanding the Kubernetes Attack Surface

The cluster that fell to one forgotten token A team at acme-shop runs an internal admin dashboard on Kubernetes.

Granting Least Privilege with RBAC

How RBAC objects fit together RBAC (role-based access control) decides who can do what in the cluster.

Hardening Service Accounts and Tokens

How pods authenticate with service accounts A service account is the identity a pod uses to call the Kubernetes API.

Enforcing Pod Security Standards

The three levels Pod Security Standards define three profiles for pod settings, and Pod Security Admission enforces them through namespace labels.

Restricting Traffic with Network Policies

Why policies need an enforcing network plugin By default every pod can talk to every other pod.

Encrypting Secrets at Rest

Why base64 is not protection Kubernetes Secrets are stored base64-encoded, which is a reversible encoding and not encryption.

Skills You'll Master

KUBERNETES-SECURITYRBACNETWORK-POLICIESPOD-SECURITYFALCO

Curriculum Index11 topics

1

Understanding the Kubernetes Attack Surface

The cluster that fell to one forgotten token A team at acme-shop runs an internal admin dashboard on Kubernetes.

2

Granting Least Privilege with RBAC

How RBAC objects fit together RBAC (role-based access control) decides who can do what in the cluster.

3

Hardening Service Accounts and Tokens

How pods authenticate with service accounts A service account is the identity a pod uses to call the Kubernetes API.

4

Enforcing Pod Security Standards

The three levels Pod Security Standards define three profiles for pod settings, and Pod Security Admission enforces...

5

Restricting Traffic with Network Policies

Why policies need an enforcing network plugin By default every pod can talk to every other pod.

6

Encrypting Secrets at Rest

Why base64 is not protection Kubernetes Secrets are stored base64-encoded, which is a reversible encoding and not...

7

Protecting etcd and the Control Plane

What etcd holds and who can reach it etcd stores every object in the cluster, including Secrets, ConfigMaps, and RBAC...

8

Enforcing Policies at Admission

What admission controllers do After a request is authenticated and authorised, admission controllers can validate or...

9

Detecting Runtime Threats with Falco

What Falco watches Everything so far prevents problems.

10

Hands-on Lab: Audit and Harden a Local Cluster

Before you start You need Docker, kind, and kubectl installed.

11

Quick Reference and Common Mistakes

Quick reference Common mistakes Granting cluster-admin to a workload is the classic shortcut, and it makes any pod...

Career Impact

Roles that use the skills in this module.

  • DevSecOps Engineer

    ₹12L - ₹30L a year

    High Demand
  • Platform Engineer

    ₹15L - ₹28L a year

    Growing
  • Site Reliability Engineer

    ₹12L - ₹28L a year

    High Demand
See how this is asked in interviews

Practice on the Coding Sheet

Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.

Open the Coding Sheet

Frequently Asked Questions

Not in the cluster itself. Secrets are base64-encoded, which is an encoding and not encryption, and they are stored in etcd. Self-managed clusters need encryption at rest configured on the API server, while managed services such as EKS, GKE, and AKS handle storage encryption in provider settings.

No. A NetworkPolicy object is accepted by the API on any cluster, but it is enforced only if the network plugin supports it, such as Calico or Cilium. Without an enforcing plugin, a default-deny policy appears to apply while blocking nothing.

Pod Security Admission, which enforces the three Pod Security Standards (privileged, baseline, restricted) through namespace labels. PodSecurityPolicy was removed in Kubernetes 1.25.

The default account is shared by every pod in the namespace that does not name another one, so any permission you grant it reaches all of them. Give each workload its own service account with only the permissions it needs, and disable token mounting where the pod never calls the API.