kubernetes-security-audit

v2026.09.25

Audit Kubernetes clusters for RBAC excesses, pod security gaps, network policy holes, and supply-chain risks. Use when reviewing cluster configuration or hardening deployments.

GitHub
安装命令
npx skhub add securityskills/kubernetes-security-audit
Markdown
SKILL.md

Kubernetes Security Audit

Audit a cluster across four layers: workload, identity, network, supply chain.

Workload Security

  • Pod Security Standards: check namespace labels (pod-security.kubernetes.io/enforce)
  • Privileged pods, hostPID/hostNetwork/hostPath usage — each needs justification
  • Containers running as root; allowPrivilegeEscalation: true; missing readOnlyRootFilesystem
  • securityContext set at pod and container level; capabilities dropped to minimum set

RBAC

  • Enumerate bindings; find cluster-admin subjects — minimize to a named list
  • Escalation paths: bind/escalate/impersonate verbs; create pods + node privileged, create pods/exec
  • Service accounts: default SA used by workloads? token automount disabled where unneeded?
  • Check for wildcard (*) verbs/resources in custom roles

Network

  • NetworkPolicy: default-deny ingress/egress per namespace as the baseline
  • Cross-namespace exposure: which namespaces can reach kube-system, ingress controllers, databases
  • Control plane exposure: API server on public IP? etcd reachable/authenticated?

Supply Chain

  • Image provenance: registry digests pinned (not :latest), signature verification (cosign)
  • Admission control: image policy, no privileged images from untrusted registries
  • Secrets: Kubernetes Secrets at rest (KMS encryption configured), not baked into images or env in manifests committed to git

Quick Checks

kubectl get pods -A -o json | jq '[.items[] | select(.spec.containers[].securityContext.privileged==true)]'
kubectl get ns -l pod-security.kubernetes.io/enforce
kubectl auth can-i --list --as=system:serviceaccount:default:default
kubectl get networkpolicy -A

Output

Findings per layer with YAML evidence, risk, and hardening manifests for remediation.

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.25

发布时间

2026年9月25日

分类

未分类

许可证

未指定

源路径

container-security/kubernetes/kubernetes-security-audit

默认分支

main

最新提交

b2b6b52

Tree SHA

8db485b