K8s Security Policies

by wshobson46891e7e60daNo licenseListed Oct 8, 2026Updated Oct 8, 2026

Implement Kubernetes security policies including NetworkPolicy, PodSecurityPolicy, and RBAC for production-grade security. Use when securing Kubernetes clusters, implementing network isolation, or enforcing pod security standards.

Instructions onlySecurityDevOps & Cloud
AI-generated overview

Guides implementation of Kubernetes security policies: NetworkPolicy, Pod Security Standards, RBAC, and admission control.

What it does
This skill provides reference guidance and YAML examples for hardening Kubernetes clusters, covering Pod Security Standards, NetworkPolicy segmentation, RBAC roles and bindings, secure pod security contexts, OPA Gatekeeper constraints, and Istio mTLS authorization. It also lists best practices, compliance mappings (CIS, NIST), and troubleshooting commands. It ships a network policy template asset and an RBAC patterns reference document.
When to use it
Use it when securing Kubernetes clusters, implementing network isolation or segmentation, enforcing pod security standards, or setting up least-privilege RBAC. It also fits compliance-oriented policy work and multi-tenant cluster hardening.
Requirements
No scripts; instructions and YAML examples only. Working with the examples assumes a Kubernetes cluster and kubectl, and some sections reference OPA Gatekeeper or Istio if those are used.

Kubernetes Security Policies

Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.

Purpose

Implement defense-in-depth security for Kubernetes clusters using network policies, pod security standards, and RBAC.

When to Use This Skill

  • Implement network segmentation
  • Configure pod security standards
  • Set up RBAC for least-privilege access
  • Create security policies for compliance
  • Implement admission control
  • Secure multi-tenant clusters

Pod Security Standards

1. Privileged (Unrestricted)

yaml
apiVersion: v1kind: Namespacemetadata:  name: privileged-ns  labels:    pod-security.kubernetes.io/enforce: privileged    pod-security.kubernetes.io/audit: privileged    pod-security.kubernetes.io/warn: privileged

2. Baseline (Minimally restrictive)

yaml
apiVersion: v1kind: Namespacemetadata:  name: baseline-ns  labels:    pod-security.kubernetes.io/enforce: baseline    pod-security.kubernetes.io/audit: baseline    pod-security.kubernetes.io/warn: baseline

3. Restricted (Most restrictive)

yaml
apiVersion: v1kind: Namespacemetadata:  name: restricted-ns  labels:    pod-security.kubernetes.io/enforce: restricted    pod-security.kubernetes.io/audit: restricted    pod-security.kubernetes.io/warn: restricted

Network Policies

Default Deny All

yaml
apiVersion: networking.k8s.io/v1kind: NetworkPolicymetadata:  name: default-deny-all  namespace: productionspec:  podSelector: {}  policyTypes:    - Ingress    - Egress

Allow Frontend to Backend

yaml
apiVersion: networking.k8s.io/v1kind: NetworkPolicymetadata:  name: allow-frontend-to-backend  namespace: productionspec:  podSelector:    matchLabels:      app: backend  policyTypes:    - Ingress  ingress:    - from:        - podSelector:            matchLabels:              app: frontend      ports:        - protocol: TCP          port: 8080

Allow DNS

yaml
apiVersion: networking.k8s.io/v1kind: NetworkPolicymetadata:  name: allow-dns  namespace: productionspec:  podSelector: {}  policyTypes:    - Egress  egress:    - to:        - namespaceSelector:            matchLabels:              name: kube-system      ports:        - protocol: UDP          port: 53

Reference: See assets/network-policy-template.yaml

RBAC Configuration

Role (Namespace-scoped)

yaml
apiVersion: rbac.authorization.k8s.io/v1kind: Rolemetadata:  name: pod-reader  namespace: productionrules:  - apiGroups: [""]    resources: ["pods"]    verbs: ["get", "watch", "list"]

ClusterRole (Cluster-wide)

yaml
apiVersion: rbac.authorization.k8s.io/v1kind: ClusterRolemetadata:  name: secret-readerrules:  - apiGroups: [""]    resources: ["secrets"]    verbs: ["get", "watch", "list"]

RoleBinding

yaml
apiVersion: rbac.authorization.k8s.io/v1kind: RoleBindingmetadata:  name: read-pods  namespace: productionsubjects:  - kind: User    name: jane    apiGroup: rbac.authorization.k8s.io  - kind: ServiceAccount    name: default    namespace: productionroleRef:  kind: Role  name: pod-reader  apiGroup: rbac.authorization.k8s.io

Reference: See references/rbac-patterns.md

Pod Security Context

Restricted Pod

yaml
apiVersion: v1kind: Podmetadata:  name: secure-podspec:  securityContext:    runAsNonRoot: true    runAsUser: 1000    fsGroup: 1000    seccompProfile:      type: RuntimeDefault  containers:    - name: app      image: myapp:1.0      securityContext:        allowPrivilegeEscalation: false        readOnlyRootFilesystem: true        capabilities:          drop:            - ALL

Policy Enforcement with OPA Gatekeeper

ConstraintTemplate

yaml
apiVersion: templates.gatekeeper.sh/v1kind: ConstraintTemplatemetadata:  name: k8srequiredlabelsspec:  crd:    spec:      names:        kind: K8sRequiredLabels      validation:        openAPIV3Schema:          type: object          properties:            labels:              type: array              items:                type: string  targets:    - target: admission.k8s.gatekeeper.sh      rego: |        package k8srequiredlabels        violation[{"msg": msg, "details": {"missing_labels": missing}}] {          provided := {label | input.review.object.metadata.labels[label]}          required := {label | label := input.parameters.labels[_]}          missing := required - provided          count(missing) > 0          msg := sprintf("missing required labels: %v", [missing])        }

Constraint

yaml
apiVersion: constraints.gatekeeper.sh/v1beta1kind: K8sRequiredLabelsmetadata:  name: require-app-labelspec:  match:    kinds:      - apiGroups: ["apps"]        kinds: ["Deployment"]  parameters:    labels: ["app", "environment"]

Service Mesh Security (Istio)

PeerAuthentication (mTLS)

yaml
apiVersion: security.istio.io/v1beta1kind: PeerAuthenticationmetadata:  name: default  namespace: productionspec:  mtls:    mode: STRICT

AuthorizationPolicy

yaml
apiVersion: security.istio.io/v1beta1kind: AuthorizationPolicymetadata:  name: allow-frontend  namespace: productionspec:  selector:    matchLabels:      app: backend  action: ALLOW  rules:    - from:        - source:            principals: ["cluster.local/ns/production/sa/frontend"]

Best Practices

  1. Implement Pod Security Standards at namespace level
  2. Use Network Policies for network segmentation
  3. Apply least-privilege RBAC for all service accounts
  4. Enable admission control (OPA Gatekeeper/Kyverno)
  5. Run containers as non-root
  6. Use read-only root filesystem
  7. Drop all capabilities unless needed
  8. Implement resource quotas and limit ranges
  9. Enable audit logging for security events
  10. Regular security scanning of images

Compliance Frameworks

CIS Kubernetes Benchmark

  • Use RBAC authorization
  • Enable audit logging
  • Use Pod Security Standards
  • Configure network policies
  • Implement secrets encryption at rest
  • Enable node authentication

NIST Cybersecurity Framework

  • Implement defense in depth
  • Use network segmentation
  • Configure security monitoring
  • Implement access controls
  • Enable logging and monitoring

Troubleshooting

NetworkPolicy not working:

bash
# Check if CNI supports NetworkPolicykubectl get nodes -o widekubectl describe networkpolicy <name>

RBAC permission denied:

bash
# Check effective permissionskubectl auth can-i list pods --as system:serviceaccount:default:my-sakubectl auth can-i '*' '*' --as system:serviceaccount:default:my-sa

Related Skills

  • k8s-manifest-generator - For creating secure manifests
  • gitops-workflow - For automated policy deployment

Source and attribution

Source:wshobson/agentsinplugins/kubernetes-operations/skills/k8s-security-policiesat commit46891e7

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal