πŸ“šBook Signing at KubeCon EU 2026Meet us at Booking.com HQ (Mon 18:30-21:00) & vCluster booth #521 (Tue 24 Mar, 12:30-1:30pm) β€” free book giveaway!RSVP Booking.com Event

πŸ”’ Security

Kubernetes security recipes: RBAC, Pod Security Standards, Network Policies, secrets, image scanning, RHACS, and compliance automation.

160 recipes 🟒 4 beginner 🟑 98 intermediate πŸ”΄ 58 advanced
advanced ⏱ 15 minutes

Kubernetes Audit Logging Configuration

Configure Kubernetes audit logging to track API requests. Define audit policies, capture who did what and when, send logs to backends like

audit-loggingsecuritycomplianceapi-server
intermediate ⏱ 15 minutes

Kubernetes gVisor and Kata Containers RuntimeClass

Deploy sandboxed container runtimes on Kubernetes using RuntimeClass with gVisor (runsc) and Kata Containers. Isolate untrusted workloads with kernel-level

gvisorkata-containersruntimeclasssecurity
intermediate ⏱ 15 minutes

Default Deny NetworkPolicy: Zero-Trust Examples

Implement default deny network policies in Kubernetes for zero-trust pod networking. Block all ingress and egress by default, then allow only required traffic

networkpolicysecurityzero-trustnetworking
intermediate ⏱ 15 minutes

Kubernetes Secrets Management Best Practices

Manage Kubernetes Secrets securely with best practices. External Secrets Operator, sealed secrets, RBAC restrictions, encryption at rest, secret

secretssecurityexternal-secretsvault
intermediate ⏱ 15 minutes

Container Image Security Scanning on Kubernetes

Implement container image security scanning in Kubernetes CI/CD pipelines. Trivy, Grype, and admission controllers to prevent vulnerable images from running.

securitycontainer-imagestrivyvulnerability-scanning
advanced ⏱ 15 minutes

Container Image Signing and Verification on Kubernetes

Sign container images with Sigstore cosign and verify signatures at admission time with Kyverno or Connaisseur. Supply chain security for Kubernetes

cosignsigstoresupply-chain-securityimage-signing
intermediate ⏱ 15 minutes

ServiceAccount for Running Pods

Configure Kubernetes ServiceAccounts for Pods: token mounting, RBAC permissions, workload identity, automountServiceAccountToken control, and least-privilege

serviceaccountrbacsecuritypod-identity
intermediate ⏱ 15 minutes

OpenShift User Account Management

Manage user accounts in OpenShift: create users, assign roles, configure identity providers, manage groups, and implement RBAC for multi-tenant clusters.

openshiftuser-managementrbacidentity-provider
advanced ⏱ 15 minutes

Kyverno AI Workload Provenance Verification

Use Kyverno to verify software and content provenance for AI workloads: SBOM validation, model signing with Sigstore, dataset integrity, and supply chain

kyvernosupply-chainai-securitysigstore
advanced ⏱ 15 minutes

Kyverno CEL Policy Model Migration

Migrate Kyverno policies from YAML-based rules to CEL expressions for type-safe, performant validation. Covers CEL syntax, migration patterns, and comparison

kyvernocelpolicyadmission-control
intermediate ⏱ 15 minutes

Kyverno Drift Prevention for GitOps

Prevent configuration drift in GitOps workflows using Kyverno: block manual kubectl edits, enforce ArgoCD/Flux ownership, and detect out-of-band changes

kyvernogitopsargocddrift-detection
advanced ⏱ 15 minutes

Kyverno ISO 27001 Compliance Policies

Implement ISO 27001 and BSI IT-Grundschutz security controls in Kubernetes using Kyverno policies: access control, cryptography, operations security, and audit

kyvernocomplianceiso27001security
advanced ⏱ 15 minutes

Kyverno LLM Inference Cost and Security Guardrails

Implement policy-as-code guardrails for LLM inference workloads with Kyverno: GPU quota enforcement, model size limits, cost controls, prompt injection

kyvernollminferencecost-management
advanced ⏱ 15 minutes

Kyverno ReBAC Multi-Tenant RBAC Automation

Implement Relationship-Based Access Control (ReBAC) with Kyverno to automate multi-tenant RBAC at scale: dynamic RoleBindings, namespace

kyvernorbacmulti-tenancyrebac
advanced ⏱ 15 minutes

Kyverno Webhook Topology and Admission Latency

Optimize Kyverno webhook topology for minimal admission latency: webhook configuration tuning, failure policies, timeout settings, and lessons from migrating

kyvernowebhookadmission-controlperformance
intermediate ⏱ 15 minutes

External Secrets Operator on OpenShift

Manage Kubernetes secrets from external vaults using External Secrets Operator on OpenShift. Covers ExternalSecret CRD, SecretStore configuration, and GitOps

secretssecurityopenshiftgitops
intermediate ⏱ 15 minutes

Run:ai Keycloak SSO Authentication Setup

Configure Run:ai SSO authentication with Keycloak on OpenShift: OIDC integration, user federation, role mapping, and troubleshooting login failures.

runaikeycloakssoauthentication
intermediate ⏱ 15 minutes

CVE-2026-31431 Linux Kernel Crypto Fix

Security advisory for CVE-2026-31431: Linux kernel crypto algif_aead vulnerability. Impact on Kubernetes nodes and how to patch container host kernels.

securitycvelinux-kernelnode-security
advanced ⏱ 15 minutes

Kubernetes 1.36 Constrained Impersonation

Use constrained impersonation in Kubernetes 1.36 to limit which identities a user can impersonate. Tighter RBAC control for multi-tenant clusters.

kubernetes-1.36rbacsecurityimpersonation
advanced ⏱ 15 minutes

Kubernetes 1.36 External SA Token Signing

Delegate ServiceAccount token signing to external KMS or HSM systems in Kubernetes 1.36. Improve security with hardware-backed key management.

kubernetes-1.36service-accountssecuritykms
advanced ⏱ 15 minutes

Kubernetes 1.36 Pod Certificates (mTLS)

Use Pod Certificates in Kubernetes 1.36 to authenticate Pods to the API server via mTLS. Built-in X.509 certificate provisioning without external tools.

kubernetes-1.36securitymtlscertificates
intermediate ⏱ 15 minutes

Kubernetes 1.36 SELinux Mount-Time Labeling

Configure SELinux mount-time volume labeling in Kubernetes 1.36 to eliminate slow recursive relabeling and speed up Pod startup times dramatically.

kubernetes-1.36selinuxsecurityvolumes
advanced ⏱ 15 minutes

Kubernetes 1.36 User Namespaces in Pods

Enable user namespaces in Kubernetes 1.36 for rootless containers and stronger Pod isolation. Map container root to unprivileged host UIDs.

kubernetes-1.36user-namespacessecurityrootless
advanced ⏱ 12 minutes

SPIFFE/SPIRE: Workload Identity for K8s

Deploy SPIRE for Kubernetes workload identity using SPIFFE standards. Automatic mTLS certificate issuance, cross-cluster identity federation.

spiffespireidentityzero-trust
advanced ⏱ 20 minutes

Kata Containers RuntimeClass Kubernetes

Deploy Kata Containers with Kubernetes RuntimeClass for hardware-isolated pods. VM-based sandboxing, microVM configuration, and multi-runtime clusters.

kata-containersruntimeclasssecuritysandboxing
advanced ⏱ 15 minutes

K8s Admission Webhooks: Validate and Mutate

Build Kubernetes validating and mutating admission webhooks. Webhook configuration, TLS setup, failure policies, and common patterns for policy enforcement.

admission-webhookssecuritypolicyvalidation
advanced ⏱ 12 minutes

K8s Audit Logging: Track API Activity

Configure Kubernetes audit logging to track API requests. Audit policy levels, log backends, webhook integration, and security compliance monitoring.

auditsecurityloggingcompliance
intermediate ⏱ 12 minutes

cert-manager: Automated TLS Certificates

Automate TLS certificate management with cert-manager in Kubernetes. Let's Encrypt integration, Issuer configuration, wildcard certificates, and automatic

tlscertificatescert-managersecurity
advanced ⏱ 12 minutes

K8s Certificate Rotation and Management

Manage Kubernetes cluster certificates with kubeadm. Check expiration, renew certificates, configure auto-rotation, and troubleshoot TLS errors.

certificatestlssecurityadministration
intermediate ⏱ 10 minutes

External Secrets Operator: Vault and Cloud

Sync secrets from HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, and GCP Secret Manager into Kubernetes with External Secrets Operator.

secretsvaultsecurityexternal-secrets
advanced ⏱ 12 minutes

Falco: K8s Runtime Threat Detection

Deploy Falco for Kubernetes runtime security monitoring. Detect suspicious container behavior, privilege escalation, file access.

falcoruntime-securitysecuritythreat-detection
intermediate ⏱ 12 minutes

Harbor: Private Container Registry on K8s

Deploy Harbor container registry in Kubernetes for private image hosting. Vulnerability scanning, image replication, RBAC, Helm chart repository.

harborregistrysecuritycontainer-images
intermediate ⏱ 12 minutes

Kyverno: K8s Policy Engine Without Code

Enforce Kubernetes policies with Kyverno. Validate, mutate, and generate resources using YAML policies. Image verification, label enforcement.

kyvernopolicysecuritygovernance
intermediate ⏱ 10 minutes

K8s Pod Security Admission Standards

Configure Kubernetes Pod Security Admission with enforce, audit, and warn modes. Privileged, baseline, and restricted profiles for namespace-level pod security.

pod-securitysecurityadmission-controllernamespaces
intermediate ⏱ 12 minutes

K8s RBAC: Role and RoleBinding Guide

Configure Kubernetes RBAC with Role, ClusterRole, RoleBinding, and ClusterRoleBinding. Service account permissions, least privilege, and audit examples.

rbacsecurityservice-accountscka
beginner ⏱ 10 minutes

K8s Secrets: Types and Usage Guide

Create and manage Kubernetes Secrets: Opaque, docker-registry, TLS, and basic-auth types. Mount as volumes, inject as env vars, and encrypt at rest.

secretssecurityencryptionconfiguration
intermediate ⏱ 10 minutes

K8s SecurityContext: Container Hardening

Configure Kubernetes SecurityContext for pods and containers. runAsNonRoot, readOnlyRootFilesystem, capabilities, seccomp profiles, and privilege escalation.

security-contextsecuritycontainershardening
intermediate ⏱ 10 minutes

K8s ServiceAccount: Pod Identity Guide

Create Kubernetes ServiceAccounts for pod authentication. Token projection, RBAC binding, workload identity, automountServiceAccountToken, and OIDC federation.

service-accountssecurityrbacauthentication
intermediate ⏱ 10 minutes

Trivy: K8s Security Scanning and SBOM

Scan Kubernetes clusters with Trivy for vulnerabilities, misconfigurations, and secrets. Trivy Operator for continuous scanning, SBOM generation.

trivyvulnerability-scanningsecuritysbom
intermediate ⏱ 20 minutes

GKE OIDC Issuer Workload Identity

Enable OIDC issuer on GKE with --enable-oidc-issuer. Configure workload identity federation for cross-cloud auth and external IdP integration.

gkeoidcworkload-identitysecurity
intermediate ⏱ 18 minutes

Kubernetes NetworkPolicy Guide

Secure pod-to-pod traffic with Kubernetes NetworkPolicies. Ingress and egress rules, namespace selectors, deny-all policies, and CNI requirements.

network-policysecuritynetworkingzero-trust
intermediate ⏱ 18 minutes

Kubernetes RBAC Role ClusterRole

Configure RBAC in Kubernetes with Roles, ClusterRoles, RoleBindings, and ClusterRoleBindings. Least-privilege access for users, groups, and service accounts.

rbacsecurityaccess-controlservice-accounts
intermediate ⏱ 25 minutes

EDR Flexera Agents Kubernetes Deploy

Deploy EDR and Flexera agents on Kubernetes with DaemonSets. Priority classes, host path access, exclusion paths, and security agent lifecycle.

edrflexeracrowdstrikesecurity
intermediate ⏱ 15 minutes

OpenShift ACS RHACS Security Guide

Deploy Red Hat Advanced Cluster Security (RHACS/ACS) on OpenShift. Vulnerability scanning, compliance, runtime threat detection, and policy enforcement.

openshiftacsrhacsvulnerability-scanning
advanced ⏱ 25 minutes

RHACS NFS Tenant Security Kubernetes

Enforce NFS tenant isolation with RHACS policies. Detect direct NFS mounts, wrong StorageClass usage, privileged escalation, and cross-tenant violations.

rhacsstackroxnfsmulti-tenancy
intermediate ⏱ 20 minutes

Ubuntu 26.04 LTS K8s Node Hardening

Harden Kubernetes nodes with Ubuntu 26.04 LTS Resolute Raccoon. sudo-rs Rust rewrite, APT rollback, Kernel 7.0 TDX, ROCm GPU, and secure base images.

ubuntuhardeningsudo-rsbase-image
intermediate ⏱ 15 minutes

Certificate Expiration Management K8s

Monitor and manage Kubernetes certificate expiration. kubeadm cert check, cert-manager alerts, auto-renewal, and preventing expired certificate outages.

certificatesexpirationkubeadmrenewal
intermediate ⏱ 15 minutes

Falco Rules for Kubernetes: Complete Guide

Write custom Falco rules for K8s runtime security. Syscall detection, container escape alerts, and cryptomining detection.

falcorulesruntime-securitysyscall
intermediate ⏱ 15 minutes

Trivy Image Scanning Kubernetes

Scan container images with Trivy on K8s. Admission webhook, CI/CD integration, CIS benchmarks, and vulnerability reporting.

trivyimage-scanningvulnerabilityadmission
beginner ⏱ 10 minutes

NetworkPolicy Examples Cookbook K8s

Copy-paste Kubernetes NetworkPolicy examples. Default deny all, allow DNS, allow specific namespace, database access, and external egress patterns.

networkpolicyexamplesdenyallow
advanced ⏱ 15 minutes

K8s OIDC Authentication Login Guide

Configure OIDC authentication for Kubernetes API server. --enable-oidc-issuer with GKE, Keycloak, Dex, kubelogin plugin, and RBAC SSO integration.

oidcauthenticationssokeycloak
intermediate ⏱ 15 minutes

RBAC Audit Review Kubernetes Guide

Audit Kubernetes RBAC permissions for security compliance. Identify over-permissioned roles, service account privileges, and least-privilege enforcement.

rbacauditcomplianceleast-privilege
intermediate ⏱ 10 minutes

RuntimeClass gVisor Kubernetes

Deploy gVisor as a sandboxed container runtime on Kubernetes using RuntimeClass. Covers installation, runsc configuration, and workload isolation.

runtimeclassgvisorrunscsandbox
intermediate ⏱ 15 minutes

K8s Secrets Management Best Practices

Kubernetes secrets management best practices. Encryption at rest, external secrets operator, rotation strategies, and RBAC for secure secret handling.

secretsencryptionbest-practicesexternal-secrets
intermediate ⏱ 15 minutes

K8s Security Checklist 2026 Guide

Complete Kubernetes security checklist for 2026. RBAC audit, network policies, pod security standards, image scanning, and compliance hardening steps.

securitychecklisthardeningcompliance
intermediate ⏱ 15 minutes

OpenShift OAuth Proxy Sidecar Guide

Protect K8s services with OpenShift OAuth proxy sidecar. Authentication, RBAC delegation, and SSO for internal dashboards.

openshiftoauthproxysidecar
intermediate ⏱ 15 minutes

OpenShift SCC Security Context Guide

Configure OpenShift Security Context Constraints for pods. Restricted, anyuid, privileged SCCs, custom SCC, and migration to PSA.

openshiftsccsecurity-contextpsa
advanced ⏱ 20 minutes

AI ML Security and Compliance Kubernetes

Secure AI and ML workloads on Kubernetes with model encryption, data governance, audit logging, network isolation for training jobs.

ai-securityml-compliancemodel-encryptiondata-governance
intermediate ⏱ 20 minutes

cert-manager Advanced Configuration

Advanced cert-manager patterns for Kubernetes. Wildcard certificates, DNS-01 challenges, certificate rotation, cross-namespace sharing.

cert-managertlscertificateslets-encrypt
intermediate ⏱ 20 minutes

Cilium Network Policies Kubernetes

Advanced network policies with Cilium on Kubernetes. L7 HTTP-aware policies, DNS-based egress, identity-based security, cluster-wide policies.

ciliumnetwork-policyebpfl7-policy
intermediate ⏱ 15 minutes

Cosign Image Signing Kubernetes

Verify container image signatures with Cosign and Sigstore on Kubernetes. Policy enforcement with Kyverno, supply chain security, and SBOM attestation.

cosignsigstoreimage-signingsupply-chain
intermediate ⏱ 15 minutes

Multi-Tenancy Namespaces Kubernetes

Implement multi-tenancy on Kubernetes with namespaces. Resource quotas, network policies, RBAC isolation, and hierarchical namespaces for team separation.

multi-tenancynamespacesisolationrbac
beginner ⏱ 15 minutes

NetworkPolicy Recipes Cookbook K8s

Common Kubernetes NetworkPolicy recipes. Default deny, allow DNS, namespace isolation, database access, and external egress patterns for zero-trust networking.

network-policysecurityfirewallzero-trust
intermediate ⏱ 15 minutes

NetworkPolicy Zero Trust Kubernetes

Implement zero-trust networking with Kubernetes NetworkPolicies. Default-deny ingress and egress, namespace isolation, DNS egress rules, and Cilium L7 policies.

networkpolicyzero-trustsecuritynamespace-isolation
intermediate ⏱ 20 minutes

OPA Gatekeeper Policy Enforcement

Enforce policies with OPA Gatekeeper on Kubernetes. ConstraintTemplates, Constraints, dry-run mode, audit, and common policies for security compliance.

opagatekeeperpolicycompliance
intermediate ⏱ 15 minutes

Kubernetes Pod Security Standards Guide

Implement Pod Security Standards with Pod Security Admission. Privileged, baseline, and restricted profiles, namespace labels.

pod-securitypsastandardsrestricted
intermediate ⏱ 15 minutes

RBAC Least Privilege Kubernetes

Configure Kubernetes RBAC with least-privilege Roles, ClusterRoles, and service account bindings. Audit permissions, restrict secrets access.

rbacsecurityleast-privilegeservice-account
intermediate ⏱ 20 minutes

Sealed Secrets Management Kubernetes

Manage secrets securely with Bitnami Sealed Secrets on Kubernetes. Encrypt secrets for Git storage, cluster-scoped and namespace-scoped sealing.

sealed-secretssecretsencryptiongitops
intermediate ⏱ 15 minutes

External Secrets Management Kubernetes

Integrate Kubernetes with external secret stores using External Secrets Operator. Sync secrets from HashiCorp Vault, AWS Secrets Manager, Azure Key Vault.

secretsvaultexternal-secretssecurity
intermediate ⏱ 15 minutes

Service Account Tokens Kubernetes

Manage Kubernetes service account tokens securely. Projected volumes, bound tokens, token request API, and eliminating long-lived tokens for zero-trust aut.

service-accounttokensauthenticationprojected-volume
intermediate ⏱ 15 minutes

Service Accounts and Workload Identity

Configure Kubernetes service accounts with cloud workload identity for AWS IRSA, GCP Workload Identity, and Azure AD pod federation.

service-accountworkload-identityirsasecurity
advanced ⏱ 15 minutes

Kubernetes Certificate Signing Requests

Use the Kubernetes CSR API to issue, approve, and manage TLS certificates. Automate certificate workflows for services, users, and kubelet rotation.

certificatescsrtlspki
advanced ⏱ 15 minutes

ValidatingAdmissionPolicy with CEL

Replace admission webhooks with ValidatingAdmissionPolicy and CEL expressions for in-process, low-latency Kubernetes policy enforcement.

admission-policycelpolicyvalidation
intermediate ⏱ 20 minutes

cert-manager OVH DNS-01 Wildcard TLS

Configure cert-manager with OVH DNS-01 challenge for automated wildcard TLS certificates on k3s. Let's Encrypt production certificates with zero downtime r.

cert-managerovhdns-01tls
intermediate ⏱ 20 minutes

K8s Let's Encrypt Ingress with cert-manager

Automate TLS certificates for Kubernetes Ingress using cert-manager and Let's Encrypt. ClusterIssuer setup, HTTP-01 and DNS-01 challenges, and auto-renewal.

cert-managerletsencrypttlsingress
intermediate ⏱ 10 minutes

Kubernetes NetworkPolicy Default Deny Egress

Implement Kubernetes NetworkPolicy default deny egress rules. Block all outbound traffic, then allow specific destinations: DNS, external APIs.

networkpolicyegressdenysecurity
intermediate ⏱ 15 minutes

Kubernetes Service Account Token Guide

Create and manage Kubernetes service account tokens. TokenRequest API, projected volumes, long-lived tokens, and RBAC binding for pod-to-API authentication.

service-accounttokenrbacauthentication
advanced ⏱ 25 minutes

Automate Secret and Key Rotation in Kubernetes

Automate TLS certificate and secret key rotation in Kubernetes. CronJob-based rotation, external-secrets-operator, cert-manager auto-renewal.

secret-rotationcert-managerexternal-secretsvault
advanced ⏱ 25 minutes

Automate User Onboarding & Offboarding in K8s

Automate Kubernetes user onboarding and offboarding. RBAC provisioning, namespace creation, quota assignment, OIDC group sync, and access revocation scripts.

rbaconboardingoffboardinguser-management
intermediate ⏱ 25 minutes

OpenShift SCC: Security Context Constraints

Configure Security Context Constraints on OpenShift. Manage SCCs for pods requiring privileged access, host networking, custom UID/GID, and volume types.

sccopenshiftsecurity-contextrbac
intermediate ⏱ 25 minutes

Hardware Attestation for Kubernetes Workloads

Implement remote attestation for Kubernetes workloads. Verify TEE integrity with attestation services, release secrets to verified enclaves.

attestationconfidential-computingzero-trustkey-broker
intermediate ⏱ 25 minutes

Confidential Containers with Kata

Deploy confidential containers using Kata Containers and TEEs on Kubernetes. Hardware attestation, encrypted container images.

confidential-containerskata-containersteesev-snp
intermediate ⏱ 15 minutes

CVE-2026-3865: CSI SMB Driver Path Traversa...

Fix CVE-2026-3865 Kubernetes CSI SMB driver path traversal vulnerability. Upgrade to v1.20.1, detect malicious PersistentVolumes.

cvecsismbpath-traversal
intermediate ⏱ 20 minutes

gVisor RuntimeClass on K8s: Sandbox Pods

Deploy gVisor sandbox containers on Kubernetes using RuntimeClass. Install runsc, configure containerd, and isolate untrusted workloads with application-le.

gvisorruntimeclasssandboxcontainerd
advanced ⏱ 25 minutes

AI Security Platforms on Kubernetes

Secure AI workloads on Kubernetes. Model supply chain security, prompt injection defense, LLM output filtering, AI RBAC, GPU isolation.

ai-securityllm-securityprompt-injectionmodel-supply-chain
advanced ⏱ 25 minutes

Confidential Computing: SGX and SEV-SNP

Deploy confidential containers on Kubernetes with Intel SGX and AMD SEV-SNP. Encrypted memory, attestation, confidential VMs, Kata Containers.

confidential-computingsgxsev-snptrusted-execution
advanced ⏱ 20 minutes

Data Sovereignty and Geopatriation

Implement data sovereignty and geopatriation on Kubernetes. Multi-region clusters, data residency policies, sovereign cloud, GDPR compliance.

data-sovereigntygeopatriationgdprmulti-region
advanced ⏱ 20 minutes

Digital Provenance and Content Authenticity

Implement digital provenance on Kubernetes with C2PA content credentials. Verify AI-generated content, sign media pipelines.

digital-provenancec2pacontent-authenticityai-generated-content
intermediate ⏱ 15 minutes

Kubernetes NetworkPolicy Default Deny Examples

Create Kubernetes NetworkPolicy default deny rules for ingress and egress. Block all traffic, allow specific pods, DNS exceptions, and namespace isolation.

networkpolicydefault-denynetwork-securitynamespace-isolation
advanced ⏱ 20 minutes

Post-Quantum Cryptography on Kubernetes

Prepare Kubernetes clusters for post-quantum cryptography. NIST PQC standards, hybrid TLS certificates, quantum-safe mTLS, Istio/Cilium integration.

post-quantumcryptographypqctls
advanced ⏱ 20 minutes

Preemptive Cybersecurity on Kubernetes

Implement preemptive cybersecurity on Kubernetes. Threat prediction, automated vulnerability patching, runtime behavior analysis, CNAPP.

preemptive-securitythreat-detectioncnappvulnerability-management
advanced ⏱ 30 minutes

Sovereign Air-Gapped Kubernetes Clusters

Deploy sovereign and air-gapped Kubernetes clusters. Offline installation, private registry mirrors, disconnected GitOps, sovereign cloud.

air-gappedsovereignofflineprivate-registry
intermediate ⏱ 15 minutes

CVE-2026-4342: ingress-nginx Code Execution...

Patch CVE-2026-4342 in ingress-nginx β€” a CVSS 8.8 configuration injection vulnerability enabling arbitrary code execution. Upgrade to v1.13.9, v1.14.

cveingress-nginxsecurityvulnerability
advanced ⏱ 35 minutes

K8s Audit Logging for Enterprise Compliance

Configure API server audit logging for SOC2, HIPAA, and PCI-DSS compliance. Structured audit policies, log shipping, and alerting on suspicious activity.

audit-loggingcompliancesoc2pci-dss
advanced ⏱ 40 minutes

Enterprise Container Image Governance

Enforce image policies with admission controllers. Require signed images, block public registries, and automate vulnerability scanning gates.

image-governanceadmission-controllerscosignkyverno
advanced ⏱ 40 minutes

Automated Secret Rotation on Kubernetes

Implement zero-downtime secret rotation with External Secrets Operator, HashiCorp Vault dynamic secrets, and rolling restarts for enterprise compliance.

secret-rotationvaultexternal-secretscompliance
advanced ⏱ 50 minutes

Kubernetes Multi-Tenancy for Enterprise Teams

Implement secure multi-tenancy with namespace isolation, ResourceQuotas, NetworkPolicies, hierarchical namespaces, and vCluster for strong isolation.

multi-tenancynamespace-isolationresource-quotasnetwork-policies
advanced ⏱ 45 minutes

K8s OIDC Integration with Enterprise SSO

Configure Kubernetes API server OIDC authentication with Keycloak, Azure AD, or Okta for enterprise single sign-on and group-based RBAC.

oidcenterprise-ssokeycloakrbac
intermediate ⏱ 15 minutes

Falco Runtime Security for Kubernetes

Deploy Falco for Kubernetes runtime threat detection. Detect shell spawns in containers, privilege escalation, sensitive file access, and suspicious network

falcoruntime-securitythreat-detectionintrusion-detection
intermediate ⏱ 15 minutes

Secrets Encryption Rotation K8s Guide

Manage Kubernetes Secrets for passwords, tokens, and certificates. Covers creation, encryption at rest, external secret operators, and security best practices.

secretsencryptionsecuritycredentials
intermediate ⏱ 15 minutes

Kubernetes Service Accounts Guide

Create and manage Kubernetes service accounts for pod identity. Covers RBAC binding, token projection, workload identity, and least-privilege access

service-accountrbactokensworkload-identity
advanced ⏱ 15 minutes

Kubernetes Multi-Tenancy Patterns

Implement multi-tenancy in Kubernetes with namespaces, RBAC, quotas, network policies, and virtual clusters. Covers soft and hard tenancy models.

multi-tenancynamespacesisolationquotas
intermediate ⏱ 15 minutes

Kubernetes Security Checklist for Production

Production security checklist for Kubernetes clusters. Covers RBAC, network policies, pod security, secrets encryption, audit logging, and image scanning.

security-checklisthardeningproductioncompliance
intermediate ⏱ 15 minutes

K8s RBAC: Roles, ClusterRoles, and Bindings

Configure Kubernetes RBAC with Roles, ClusterRoles, RoleBindings, and service accounts. Least privilege access control for users, groups, and applications.

rbacrolesclusterrolerolebinding
beginner ⏱ 15 minutes

Kubernetes Secrets: Create, Use, and Secure

Create and manage Kubernetes Secrets for sensitive data. Covers types, encoding, mounting, external secrets operators, and encryption at rest best practices.

secretssecurityencryptionbase64
advanced ⏱ 15 minutes

Fix Kubernetes Certificate Expiry Issues

Debug and renew expired Kubernetes certificates for API server, kubelet, and etcd. Covers kubeadm cert renewal, OpenShift auto-rotation, and monitoring expiry.

certificatestlsexpirykubeadm
advanced ⏱ 15 minutes

Confidential Computing on Kubernetes

Deploy confidential containers with encrypted memory using Intel SGX, AMD SEV-SNP, and Kata Containers. Protect data in use from even the cluster admin.

confidential-computingsgxsev-snpkata-containers
advanced ⏱ 15 minutes

Kubernetes Admission Controllers and Webhooks

Build validating and mutating admission webhooks for Kubernetes. Policy enforcement with OPA Gatekeeper, Kyverno, and custom webhooks.

admission-controllerswebhooksopakyverno
intermediate ⏱ 15 minutes

Kubernetes Secrets Management Patterns

Kubernetes secrets management best practices 2026: External Secrets Operator, Vault, Sealed Secrets, SOPS, encryption at rest, and rotation.

secretsvaultexternal-secretsencryption
intermediate ⏱ 15 minutes

K8s Service Accounts and Token Management

Configure service accounts, bound tokens, OIDC federation, and workload identity for Kubernetes. Migrate from legacy tokens to projected volumes.

service-accountstokensoidcworkload-identity
intermediate ⏱ 15 minutes

Fix RBAC Permission Denied Errors

Debug RBAC forbidden and unauthorized errors in Kubernetes. Covers ClusterRole vs Role scope and service account permissions.

rbacforbiddenpermissionsserviceaccount
advanced ⏱ 30 minutes

Harden Kubernetes Security Posture

Kubernetes security hardening: Pod Security Standards, RBAC least-privilege, network policies, secret encryption, and audit logging.

securityhardeningpssrbac
advanced ⏱ 30 minutes

OpenClaw API Keys External Secrets Operator

Manage OpenClaw API keys and gateway tokens using External Secrets Operator with AWS Secrets Manager, Vault, or GCP Secret Manager on Kubernetes.

openclawexternal-secretsvaultaws-secrets-manager
intermediate ⏱ 20 minutes

OpenClaw Pod Security Hardening on Kubernetes

Harden OpenClaw pods with read-only filesystem, dropped capabilities, non-root user, seccomp profiles, and resource limits.

openclawpod-securityhardeningseccomp
intermediate ⏱ 15 minutes

Quay Default Permissions for Robot Accounts

Configure Quay Registry default permissions to auto-grant read access to robot accounts on every new repository. API and team patterns.

quayrobot-accountpermissionsregistry
intermediate ⏱ 20 minutes

Add Custom CA Certificates in Kubernetes

Configure custom Certificate Authority trust in vanilla Kubernetes using ConfigMap mounts, node-level trust stores, and containerd registry configuration.

certificatescatlssecurity
intermediate ⏱ 20 minutes

Add Custom CA Certificates in OpenShift

Configure custom Certificate Authority trust across an OpenShift cluster using proxy config, image config, and automatic CA bundle injection into pods.

openshiftcertificatescatls
intermediate ⏱ 25 minutes

Add Custom CA in OpenShift and Kubernetes

Configure custom Certificate Authority trust in both OpenShift and vanilla Kubernetes for private registries, internal services, and corporate PKI.

certificatescatlsopenshift
intermediate ⏱ 15 minutes

GPU Tenant Bootstrap Bundle for Kubernetes

Provision GPU tenants with a single Kustomize bundle containing namespace, RBAC, NetworkPolicy, quotas, and HAProxy VIP config.

multi-tenantkustomizegputenant
intermediate ⏱ 15 minutes

Multi-Tenant GPU Namespace Isolation

Isolate GPU workloads across tenants using namespaces, RBAC, NetworkPolicy, and ResourceQuotas on OpenShift and Kubernetes.

multi-tenantgpunamespaceisolation
intermediate ⏱ 15 minutes

NetworkPolicy Deny-Default for GPU Tenants

Implement deny-by-default NetworkPolicy for GPU tenant namespaces with NCCL port exceptions and DNS egress on Kubernetes.

networkpolicymulti-tenantgpunccl
intermediate ⏱ 15 minutes

Network Policies for OpenClaw on Kubernetes

Secure OpenClaw deployments with Kubernetes NetworkPolicies to restrict egress to messaging APIs, block unauthorized ingress, and isolate the gateway.

openclawnetwork-policysecurityegress
advanced ⏱ 15 minutes

OpenClaw RBAC and Multi-Tenant Isolation

Configure OpenClaw RBAC policies and namespace isolation for multi-tenant Kubernetes clusters with per-team agent access controls.

openclawrbacmulti-tenancysecurity
intermediate ⏱ 20 minutes

Secure Secrets Management for OpenClaw

Manage API keys, bot tokens, and credentials for OpenClaw on Kubernetes using Kubernetes Secrets, External Secrets Operator, and Sealed Secrets.

openclawsecretssecurityapi-keys
advanced ⏱ 15 minutes

OpenShift ACS Security for Kubernetes

Deploy and configure Red Hat Advanced Cluster Security (ACS/RHACS) for vulnerability scanning, compliance, network policies, and runtime threat detection.

openshiftacsrhacsstackrox
intermediate ⏱ 25 minutes

Filter CatalogSource Operators by Package

Curate a minimal CatalogSource with only approved operators using opm index pruning and file-based catalog filtering for security and compliance.

catalogsourceolmoperatorssecurity
intermediate ⏱ 20 minutes

OpenShift Cluster-Wide Pull Secret Robot Ac...

Replace admin credentials in the OpenShift cluster-wide pull secret with a Quay robot account for secure, auditable container image pulls across all namespaces.

openshiftquaypull-secretsecurity
intermediate ⏱ 15 minutes

OpenShift Custom CA for Private Registries

Configure OpenShift to trust a custom Certificate Authority for private container registries using additionalTrustedCA and image.config.openshift.io settings.

openshiftcertificatestlscontainer-registry
intermediate ⏱ 15 minutes

RHACS Compliance Scanning in OpenShift

Run CIS, NIST, PCI DSS, and HIPAA compliance scans with Red Hat Advanced Cluster Security and automate reporting for audits.

openshiftacsrhacscompliance
advanced ⏱ 15 minutes

RHACS Custom Security Policies Guide

Create and manage custom security policies in Red Hat Advanced Cluster Security for image scanning, deployment config, and runtime enforcement.

openshiftacsrhacsstackrox
advanced ⏱ 15 minutes

RHACS Multi-Cluster Management

Manage security across multiple Kubernetes clusters with RHACS Central hub, secured cluster registration, and unified policy enforcement.

openshiftacsrhacsmulti-cluster
advanced ⏱ 15 minutes

RHACS Network Segmentation Policies

Use Red Hat Advanced Cluster Security network graph to discover traffic flows, generate NetworkPolicies, and enforce micro-segmentation.

openshiftacsrhacsnetworkpolicy
intermediate ⏱ 15 minutes

RHACS CI/CD Pipeline Integration

Integrate Red Hat Advanced Cluster Security into CI/CD pipelines with roxctl for image scanning, policy checks, and deployment validation.

openshiftacsrhacscicd
intermediate ⏱ 15 minutes

Rotate Quay Robot Tokens in Kubernetes

Automate Quay robot account token rotation across Kubernetes namespaces with zero-downtime credential updates and validation scripts.

quaysecuritysecretsrotation
advanced ⏱ 45 minutes

Update CA Certificates in Kubernetes

Rotate and update Certificate Authority (CA) certificates in Kubernetes clusters including kube-apiserver, etcd, kubelet, and custom CA bundles for TLS.

certificatescatlssecurity
intermediate ⏱ 20 minutes

SELinux and SCC Config for GPU Operator

Understand SELinux device relabeling and Security Context Constraints (SCC) requirements for the NVIDIA GPU Operator driver pods on OpenShift.

nvidiagpu-operatorselinuxscc
intermediate ⏱ 30 minutes

Deploy a New Certificate Each OpenShift Tenant

Replace and activate new TLS certificates tenant by tenant in OpenShift IngressController deployments with verification steps and rollback guidance.

openshifttlscertificatesingresscontroller
intermediate ⏱ 20 minutes

OpenShift Multi-Tenant TLS per IngressContr...

Set up tenant-isolated TLS in OpenShift by assigning a dedicated certificate Secret to each IngressController for multi-tenant routing security.

openshiftmulti-tenantingresstls
intermediate ⏱ 25 minutes

Rotate OpenShift Tenant Secrets Safely

Implement low-risk secret rotation in OpenShift multi-tenant environments using versioned Secrets and controlled rollouts.

openshiftmulti-tenantsecretsrotation
advanced ⏱ 45 minutes

gVisor Runtime Sandboxed Containers K8s

Deploy gVisor with Kubernetes RuntimeClass for sandboxed containers. Configure runsc runtime, pod isolation, and security hardening for untrusted code.

gvisorcontainer-runtimesandboxsecurity-isolation
advanced ⏱ 40 minutes

How to Integrate HashiCorp Vault with K8s

Securely manage secrets with HashiCorp Vault in Kubernetes. Learn to inject secrets into pods using the Vault Agent Injector and CSI Provider.

vaultsecretssecurityhashicorp
intermediate ⏱ 45 minutes

Kyverno Policy Management and Enforcement

Implement Kubernetes-native policy management using Kyverno to validate, mutate, and generate resources with declarative policies written in YAML

kyvernopolicy-as-codeadmission-controlsecurity
advanced ⏱ 50 minutes

OIDC Authentication for Kubernetes

Configure OpenID Connect (OIDC) authentication to integrate Kubernetes with identity providers like Keycloak, Okta, Azure AD, and Google for secure user.

oidcauthenticationidentity-providersso
intermediate ⏱ 20 minutes

Pod Security Context and Admission Standards

Configure Pod Security Context and Admission labels. Privileged, Baseline, Restricted standards, runAsUser, fsGroup, capabilities, and seccomp profiles.

security-contextsecuritypod-securitycontainers
intermediate ⏱ 25 minutes

How to Use Sealed Secrets for GitOps

Encrypt Kubernetes secrets for safe Git storage with Sealed Secrets. Learn to seal, manage, and rotate secrets in GitOps workflows securely.

sealed-secretsgitopssecurityencryption
intermediate ⏱ 30 minutes

How to Use Workload Identity for Cloud Access

Securely access cloud services from Kubernetes pods without static credentials. Configure Workload Identity for AWS, Azure, and GCP with IRSA, Workload.

workload-identityiamcloud-securityirsa
advanced ⏱ 15 minutes

How to Create Admission Webhooks

Build validating and mutating admission webhooks to enforce policies and modify resources. Implement custom admission controllers for Kubernetes.

admission-webhookssecurityvalidationmutation
advanced ⏱ 15 minutes

How to Configure Kubernetes API Access Control

Set up secure API server access with authentication and authorization. Configure RBAC, API groups, and audit logging for cluster security.

api-serverauthenticationauthorizationrbac
intermediate ⏱ 15 minutes

Manage K8s Certificates with cert-manager

Automate TLS certificate management with cert-manager. Configure issuers, request certificates from Let's Encrypt, and enable automatic renewal.

cert-managertlscertificateslets-encrypt
intermediate ⏱ 15 minutes

How to Implement Container Security Scanning

Scan container images for vulnerabilities before deployment. Integrate Trivy and other tools into CI/CD pipelines and runtime admission control.

securityscanningvulnerabilitiestrivy
intermediate ⏱ 15 minutes

How to Use External Secrets Operator

Sync secrets from external providers like AWS Secrets Manager, HashiCorp Vault, and Azure Key Vault into Kubernetes using External Secrets Operator.

secretsexternal-secretsvaultaws
advanced ⏱ 15 minutes

How to Configure Kubernetes Audit Logging

Enable and configure Kubernetes API audit logging. Track who did what, when, and to which resources for security compliance and troubleshooting.

auditloggingsecuritycompliance
advanced ⏱ 15 minutes

K8s RuntimeClass: gVisor and Kata Containers

Configure different container runtimes for workloads. Use gVisor, Kata Containers, or other runtimes for enhanced security and isolation.

runtimeclassgvisorkatacontainers
advanced ⏱ 15 minutes

How to Implement Advanced NetworkPolicies

Master advanced Kubernetes NetworkPolicies for fine-grained traffic control. Learn egress rules, CIDR blocks, namespace isolation, and common security.

networkpolicysecuritynetworkingisolation
intermediate ⏱ 15 minutes

How to Configure Pod Security Admission

Enforce security standards with Pod Security Admission. Configure privileged, baseline, and restricted policies at namespace level for cluster-wide.

pod-securitypsasecuritypolicies
advanced ⏱ 15 minutes

How to Encrypt Secrets at Rest with KMS

Configure Kubernetes secrets encryption at rest using external KMS providers. Learn to set up AWS KMS, GCP KMS, and Azure Key Vault encryption.

encryptionkmssecretssecurity
intermediate ⏱ 15 minutes

How to Manage Kubernetes Secrets Securely

Best practices for managing secrets in Kubernetes. Learn encryption at rest, secret rotation, and integration with external secret stores.

secretssecurityencryptionbest-practices
intermediate ⏱ 15 minutes

How to Configure Service Accounts and RBAC

Secure your Kubernetes workloads with service accounts and role-based access control. Create roles, bindings, and implement least-privilege access.

rbacservice-accountssecurityauthorization
intermediate ⏱ 25 minutes

How to Implement Pod Security Standards

Secure your Kubernetes workloads using Pod Security Standards (PSS). Learn to enforce Privileged, Baseline, and Restricted policies at the namespace level.

securitypod-securitypsspsa
intermediate ⏱ 30 minutes

How to Configure RBAC and Service Accounts

Master Kubernetes RBAC (Role-Based Access Control) to secure your cluster. Learn to create Roles, ClusterRoles, and bind them to ServiceAccounts.

rbacsecurityservice-accountrole
Luca Berton Ansible Pilot Ansible by Example Open Empower K8s Recipes Terraform Pilot CopyPasteLearn ProteinLens