Securing Kubernetes Introduction gives working platform operators and other technology professionals a practical, one-day, hands-on grounding in the processes and practices behind securing Kubernetes. Attendees leave with a clear understanding of application, Kubernetes, and container image security concerns. The material is condensed into a single fast-paced day for teams that need a working foundation before tackling deeper cluster hardening. Lecture is paired with demos and hands-on labs throughout, so every concept is reinforced with practice on a live cluster rather than slides alone.
The day opens with cloud native application security, covering new attack vectors in cloud native systems, perimeterless thinking, and defense in depth. It also covers the key security concerns and best practices for microservices. Attendees then move into container image security, securing registry clients and servers, establishing content trust, and signing and scanning images. They also learn to restrict who can pull images, reducing the odds that a tampered image reaches a production cluster.
The RBAC and control plane module configures the API server for TLS and mutual authentication and secures kubelet, kubectl, and CoreDNS. It also covers Kubernetes authentication and authorization concepts. Students work with RBAC users, service accounts, and namespaces, and integrate third-party auth providers such as OpenID Connect, LDAP, and Active Directory. This mirrors how most organizations tie cluster access back to an existing identity provider. The class concludes with logging and auditing: Kubernetes logging mechanisms, identifying important logging and metric alerts, and Kubernetes auditing and audit policy. This way, operators can spot suspicious activity before it becomes an incident. By the end, attendees have the information needed to begin securing a production-grade Kubernetes cluster.
Who Should Attend
SREs, IT Staff, Platform Operators, Technical Managers and DevOps personnel
What Attendees Will Learn
Upon completing Securing Kubernetes Introduction, attendees will be able to:
- Explain cloud native application security concerns and defense in depth
- Apply container image security practices, including signing and scanning
- Secure the Kubernetes control plane and configure RBAC
- Apply Kubernetes logging, metrics, and auditing for security monitoring
Prerequisites
Students should have taken the RX-M “Kubernetes Foundation” course or have equivalent knowledge.