K8s Security Policies

作者 wshobson46891e7e60da无许可证收录于 2026年10月8日更新于 2026年10月8日

Implement Kubernetes security policies including NetworkPolicy, PodSecurityPolicy, and RBAC for production-grade security. Use when securing Kubernetes clusters, implementing network isolation, or enforcing pod security standards.

AI 生成的概览

指导实施 Kubernetes 安全策略:NetworkPolicy、Pod 安全标准、RBAC 与准入控制。

功能
该技能提供加固 Kubernetes 集群的参考指南与 YAML 示例,涵盖 Pod 安全标准、NetworkPolicy 网络隔离、RBAC 角色与绑定、安全的 Pod 安全上下文、OPA Gatekeeper 约束以及 Istio mTLS 授权。它还列出最佳实践、合规框架对照(CIS、NIST)和故障排查命令。技能附带一个网络策略模板资产和一份 RBAC 模式参考文档。
适用场景
适用于保护 Kubernetes 集群、实施网络隔离或分段、执行 Pod 安全标准,或配置最小权限 RBAC 的场景。也适合面向合规的策略工作和多租户集群加固。
运行要求
不含脚本,仅为说明与 YAML 示例。使用这些示例需要 Kubernetes 集群和 kubectl;部分章节在使用时涉及 OPA Gatekeeper 或 Istio。

Kubernetes Security Policies

Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.

Purpose

Implement defense-in-depth security for Kubernetes clusters using network policies, pod security standards, and RBAC.

When to Use This Skill

  • Implement network segmentation
  • Configure pod security standards
  • Set up RBAC for least-privilege access
  • Create security policies for compliance
  • Implement admission control
  • Secure multi-tenant clusters

Pod Security Standards

1. Privileged (Unrestricted)

yaml
apiVersion: v1kind: Namespacemetadata:  name: privileged-ns  labels:    pod-security.kubernetes.io/enforce: privileged    pod-security.kubernetes.io/audit: privileged    pod-security.kubernetes.io/warn: privileged

2. Baseline (Minimally restrictive)

yaml
apiVersion: v1kind: Namespacemetadata:  name: baseline-ns  labels:    pod-security.kubernetes.io/enforce: baseline    pod-security.kubernetes.io/audit: baseline    pod-security.kubernetes.io/warn: baseline

3. Restricted (Most restrictive)

yaml
apiVersion: v1kind: Namespacemetadata:  name: restricted-ns  labels:    pod-security.kubernetes.io/enforce: restricted    pod-security.kubernetes.io/audit: restricted    pod-security.kubernetes.io/warn: restricted

Network Policies

Default Deny All

yaml
apiVersion: networking.k8s.io/v1kind: NetworkPolicymetadata:  name: default-deny-all  namespace: productionspec:  podSelector: {}  policyTypes:    - Ingress    - Egress

Allow Frontend to Backend

yaml
apiVersion: networking.k8s.io/v1kind: NetworkPolicymetadata:  name: allow-frontend-to-backend  namespace: productionspec:  podSelector:    matchLabels:      app: backend  policyTypes:    - Ingress  ingress:    - from:        - podSelector:            matchLabels:              app: frontend      ports:        - protocol: TCP          port: 8080

Allow DNS

yaml
apiVersion: networking.k8s.io/v1kind: NetworkPolicymetadata:  name: allow-dns  namespace: productionspec:  podSelector: {}  policyTypes:    - Egress  egress:    - to:        - namespaceSelector:            matchLabels:              name: kube-system      ports:        - protocol: UDP          port: 53

Reference: See assets/network-policy-template.yaml

RBAC Configuration

Role (Namespace-scoped)

yaml
apiVersion: rbac.authorization.k8s.io/v1kind: Rolemetadata:  name: pod-reader  namespace: productionrules:  - apiGroups: [""]    resources: ["pods"]    verbs: ["get", "watch", "list"]

ClusterRole (Cluster-wide)

yaml
apiVersion: rbac.authorization.k8s.io/v1kind: ClusterRolemetadata:  name: secret-readerrules:  - apiGroups: [""]    resources: ["secrets"]    verbs: ["get", "watch", "list"]

RoleBinding

yaml
apiVersion: rbac.authorization.k8s.io/v1kind: RoleBindingmetadata:  name: read-pods  namespace: productionsubjects:  - kind: User    name: jane    apiGroup: rbac.authorization.k8s.io  - kind: ServiceAccount    name: default    namespace: productionroleRef:  kind: Role  name: pod-reader  apiGroup: rbac.authorization.k8s.io

Reference: See references/rbac-patterns.md

Pod Security Context

Restricted Pod

yaml
apiVersion: v1kind: Podmetadata:  name: secure-podspec:  securityContext:    runAsNonRoot: true    runAsUser: 1000    fsGroup: 1000    seccompProfile:      type: RuntimeDefault  containers:    - name: app      image: myapp:1.0      securityContext:        allowPrivilegeEscalation: false        readOnlyRootFilesystem: true        capabilities:          drop:            - ALL

Policy Enforcement with OPA Gatekeeper

ConstraintTemplate

yaml
apiVersion: templates.gatekeeper.sh/v1kind: ConstraintTemplatemetadata:  name: k8srequiredlabelsspec:  crd:    spec:      names:        kind: K8sRequiredLabels      validation:        openAPIV3Schema:          type: object          properties:            labels:              type: array              items:                type: string  targets:    - target: admission.k8s.gatekeeper.sh      rego: |        package k8srequiredlabels        violation[{"msg": msg, "details": {"missing_labels": missing}}] {          provided := {label | input.review.object.metadata.labels[label]}          required := {label | label := input.parameters.labels[_]}          missing := required - provided          count(missing) > 0          msg := sprintf("missing required labels: %v", [missing])        }

Constraint

yaml
apiVersion: constraints.gatekeeper.sh/v1beta1kind: K8sRequiredLabelsmetadata:  name: require-app-labelspec:  match:    kinds:      - apiGroups: ["apps"]        kinds: ["Deployment"]  parameters:    labels: ["app", "environment"]

Service Mesh Security (Istio)

PeerAuthentication (mTLS)

yaml
apiVersion: security.istio.io/v1beta1kind: PeerAuthenticationmetadata:  name: default  namespace: productionspec:  mtls:    mode: STRICT

AuthorizationPolicy

yaml
apiVersion: security.istio.io/v1beta1kind: AuthorizationPolicymetadata:  name: allow-frontend  namespace: productionspec:  selector:    matchLabels:      app: backend  action: ALLOW  rules:    - from:        - source:            principals: ["cluster.local/ns/production/sa/frontend"]

Best Practices

  1. Implement Pod Security Standards at namespace level
  2. Use Network Policies for network segmentation
  3. Apply least-privilege RBAC for all service accounts
  4. Enable admission control (OPA Gatekeeper/Kyverno)
  5. Run containers as non-root
  6. Use read-only root filesystem
  7. Drop all capabilities unless needed
  8. Implement resource quotas and limit ranges
  9. Enable audit logging for security events
  10. Regular security scanning of images

Compliance Frameworks

CIS Kubernetes Benchmark

  • Use RBAC authorization
  • Enable audit logging
  • Use Pod Security Standards
  • Configure network policies
  • Implement secrets encryption at rest
  • Enable node authentication

NIST Cybersecurity Framework

  • Implement defense in depth
  • Use network segmentation
  • Configure security monitoring
  • Implement access controls
  • Enable logging and monitoring

Troubleshooting

NetworkPolicy not working:

bash
# Check if CNI supports NetworkPolicykubectl get nodes -o widekubectl describe networkpolicy <name>

RBAC permission denied:

bash
# Check effective permissionskubectl auth can-i list pods --as system:serviceaccount:default:my-sakubectl auth can-i '*' '*' --as system:serviceaccount:default:my-sa

Related Skills

  • k8s-manifest-generator - For creating secure manifests
  • gitops-workflow - For automated policy deployment

来源与署名

来源:wshobson/agents位于plugins/kubernetes-operations/skills/k8s-security-policies提交46891e7

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架