⚡ ~/naveed k8s
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Phase 3 — Security Module 16 of 24 Free & Open Access

Cluster Hardening & CIS Benchmarks

Complete production curriculum breakdown. Learn core architectural mechanics, study definitions in plain language, practice hands-on labs with the local minikube prod-sim cluster, and test active recall.

16 - Cluster Hardening & CIS Benchmarks

Why this matters

This is the "prevent the whole cluster from being compromised" layer — API server flags, kubelet config, RBAC hygiene, and automated auditing against a known standard.

Read this first — Definitions & Explanations

CIS Kubernetes Benchmark

A hardening checklist of secure configuration recommendations for control plane, workers, policies, and files.

API server hardening

Disable anonymous access where appropriate, restrict bind addresses, enable audit logs, use strong auth, limit dangerous admission settings.

Encryption at rest

Configure API server encryption providers so Secrets (and other resources) are encrypted in etcd — not just base64.

Keep control plane private

Don’t expose the Kubernetes API to the open internet without strong controls (VPN, private networks, locked security groups).

Patching

Nodes and components need regular updates. A “hardened once” cluster that never patches slowly becomes unsafe.

Official docs (read for detail)

Key Concepts

YouTube search terms

Hands-on lab (on prod-sim)

# Run kube-bench against your real cluster
minikube ssh -p prod-sim
  sudo docker run --pid=host -v /etc:/etc:ro -v /var:/var:ro \
    --rm aquasec/kube-bench:latest run --targets master,node,etcd
  exit
# Read the [FAIL] items — these are real, actionable findings on YOUR cluster

# Enable audit logging on the API server (minikube-specific path)
minikube ssh -p prod-sim
  sudo mkdir -p /etc/kubernetes/audit
  cat <<EOF | sudo tee /etc/kubernetes/audit/policy.yaml
apiVersion: audit.k8s.io/v1
kind: Policy
rules:
- level: Metadata
EOF
  sudo cp /etc/kubernetes/manifests/kube-apiserver.yaml /tmp/kube-apiserver.yaml.bak
  # Edit /etc/kubernetes/manifests/kube-apiserver.yaml to add:
  #   --audit-log-path=/var/log/audit.log
  #   --audit-policy-file=/etc/kubernetes/audit/policy.yaml
  # plus matching volumeMounts/volumes for the audit dir and log path.
  # Kubelet will auto-restart the static pod when the manifest changes.
  exit

# After it restarts, generate an event and check the audit log
kubectl get pods
minikube ssh -p prod-sim -- sudo tail -20 /var/log/audit.log

# Check for anonymous-auth / insecure settings
minikube ssh -p prod-sim -- sudo cat /etc/kubernetes/manifests/kube-apiserver.yaml | grep -E 'anonymous-auth|insecure'

Notes

(fill in your own words after watching + labbing)

📋 Self-Assessment Mastery Checklist (4 Competencies)
🧠 Practice Exam Questions (Module 16 MCQs)
⚡ Take Quiz & Save Progress in Tracker

Review these sample exam questions out loud, test your retrieval, and then unlock official scoring in the interactive tracker.

Question 1: CIS benchmarks help with:
  • A. Security configuration baselines for Kubernetes
  • B. Faster image builds
  • C. Cheaper LoadBalancers
  • D. Automatic Helm installs
✓ Correct Answer: A (Security configuration baselines for Kubernetes)
Option A ('Security configuration baselines for Kubernetes') is the standard production architectural best practice.
Question 2: Disabling anonymous auth / tightening API access is part of:
  • A. API server hardening
  • B. CNI MTU tuning only
  • C. PVC expansion
  • D. DNS caching
✓ Correct Answer: A (API server hardening)
Option A ('API server hardening') is the standard production architectural best practice.
Question 3: Encrypting Secrets at rest typically involves:
  • A. API server encryption configuration / KMS
  • B. Base64 in git
  • C. ConfigMaps
  • D. NodePort
✓ Correct Answer: A (API server encryption configuration / KMS)
Option A ('API server encryption configuration / KMS') is the standard production architectural best practice.
Question 4: Keeping the control plane private reduces:
  • A. Attack surface from the internet
  • B. Need for RBAC
  • C. Need for TLS
  • D. Need for updates
✓ Correct Answer: A (Attack surface from the internet)
Option A ('Attack surface from the internet') is the standard production architectural best practice.
Question 5: Regular patching of nodes/components is:
  • A. Essential hygiene
  • B. Optional if CIS passed once
  • C. Replaced by NetworkPolicy
  • D. Only needed for workers
✓ Correct Answer: A (Essential hygiene)
Option A ('Essential hygiene') is the standard production architectural best practice.
← Previous Module (15) Monitoring & Logging Next Module (17) → Pod & Workload Security