Hardens Kubernetes clusters using zero-trust models, RBAC design, and automated policy enforcement for production-grade security.
This skill provides a comprehensive toolkit for securing Kubernetes environments through defense-in-depth strategies. It enables developers and DevOps engineers to implement granular RBAC hierarchies, enforce Pod Security Standards (PSS), and manage sensitive data via the External Secrets Operator. By providing production-ready patterns for Kyverno, OPA Gatekeeper, and container image signing with Cosign, this skill ensures clusters meet rigorous compliance frameworks like SOC2, PCI-DSS, and HIPAA while simplifying the troubleshooting of complex access control and network policy issues.
主な機能
01Pod Security Standards (PSS) enforcement
02Supply chain security and image signing
031 GitHub stars
04Zero-trust network policy configuration
05Least-privilege RBAC architecture design
06Automated compliance policy generation
ユースケース
01Preparing Kubernetes clusters for SOC2 or PCI-DSS compliance audits
02Implementing automated security guardrails using Kyverno or Gatekeeper
03Troubleshooting and remediating RBAC permission errors and access issues