21 June 2026
Project: Kubernetes Security Baseline
A Kubernetes security baseline for RBAC, network policies, admission controls, image scanning, and runtime detection thinking.
This project is designed to prove container platform security depth without needing access to a private enterprise cluster.
The public repo will use a local kind cluster first, then document how the same controls map to AKS or EKS.
What the repo will include
- A local
kinddemo path. - Secure and intentionally insecure workloads.
- OPA Gatekeeper constraints for privileged pods, unsafe capabilities, host networking, and image rules.
- NetworkPolicy examples that show allowed and blocked traffic.
- Trivy scans in CI and a short runtime detection runbook.
What I want reviewers to see
The interesting part is not that a scanner runs. The interesting part is how the platform responds when a workload asks for something unsafe.
Examples:
insecure workload -> admission denied -> finding explained -> safe workload example
That flow shows the control, the developer experience, and the remediation path.
Why this matters
Kubernetes security is not one setting. It is identity, network boundaries, workload policy, image trust, runtime visibility, and documentation that engineers can actually use.
This project will show that full chain in a compact form.