Kubernetes Security Policies
Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.
Purpose
Implement defense-in-depth security for Kubernetes clusters using network policies, pod security standards, and RBAC.
When to Use This Skill
- Implement network segmentation
- Configure pod security standards
- Set up RBAC for least-privilege access
- Create security policies for compliance
- Implement admission control
- Secure multi-tenant clusters
Pod Security Standards
1. Privileged (Unrestricted)
2. Baseline (Minimally restrictive)
3. Restricted (Most restrictive)
Network Policies
Default Deny All
Allow Frontend to Backend
Allow DNS
Reference: See assets/network-policy-template.yaml
RBAC Configuration
Role (Namespace-scoped)
ClusterRole (Cluster-wide)
RoleBinding
Reference: See references/rbac-patterns.md
Pod Security Context
Restricted Pod
Policy Enforcement with OPA Gatekeeper
ConstraintTemplate
Constraint
Service Mesh Security (Istio)
PeerAuthentication (mTLS)
AuthorizationPolicy
Best Practices
- Implement Pod Security Standards at namespace level
- Use Network Policies for network segmentation
- Apply least-privilege RBAC for all service accounts
- Enable admission control (OPA Gatekeeper/Kyverno)
- Run containers as non-root
- Use read-only root filesystem
- Drop all capabilities unless needed
- Implement resource quotas and limit ranges
- Enable audit logging for security events
- Regular security scanning of images
Compliance Frameworks
CIS Kubernetes Benchmark
- Use RBAC authorization
- Enable audit logging
- Use Pod Security Standards
- Configure network policies
- Implement secrets encryption at rest
- Enable node authentication
NIST Cybersecurity Framework
- Implement defense in depth
- Use network segmentation
- Configure security monitoring
- Implement access controls
- Enable logging and monitoring
Troubleshooting
NetworkPolicy not working:
RBAC permission denied:
Related Skills
k8s-manifest-generator- For creating secure manifestsgitops-workflow- For automated policy deployment


