⚡ ~/naveed k8s
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Phase 3 — Security Module 17 of 24 Free & Open Access

Pod & Workload Security

Complete production curriculum breakdown. Learn core architectural mechanics, study definitions in plain language, practice hands-on labs with the local minikube prod-sim cluster, and test active recall.

17 - Pod & Workload Security

Why this matters

Even a hardened cluster is exposed if any pod can run privileged, mount the host filesystem, or escalate to root. This is the layer that stops container breakout.

Read this first — Definitions & Explanations

Run as non-root

Containers should not run as UID 0 unless absolutely required. Reduces blast radius if compromised.

Pod Security Admission (PSA)

Built-in admission that enforces Pod Security Standards profiles (privileged, baseline, restricted) per namespace.

allowPrivilegeEscalation: false

Prevents a process from gaining more privileges than its parent (important hardening flag).

readOnlyRootFilesystem

Makes container root filesystem read-only so malware can’t easily write binaries to disk (app must support it).

Capabilities / seccomp / AppArmor

Drop Linux capabilities you don’t need; use seccomp/AppArmor profiles to restrict syscalls and behavior.

Official docs (read for detail)

Key Concepts

YouTube search terms

Hands-on lab (on prod-sim)

# Enforce restricted PSA on a namespace
kubectl create namespace locked-down
kubectl label namespace locked-down \
  pod-security.kubernetes.io/enforce=restricted \
  pod-security.kubernetes.io/enforce-version=latest

# Try to run a privileged pod — should be REJECTED outright
kubectl run priv --image=nginx -n locked-down --overrides='
{"spec":{"containers":[{"name":"priv","image":"nginx","securityContext":{"privileged":true}}]}}'
# expect: Error from server (Forbidden): violates PodSecurity "restricted:latest"

# Try a compliant pod
cat <<EOF | kubectl apply -f -
apiVersion: v1
kind: Pod
metadata:
  name: safe-pod
  namespace: locked-down
spec:
  securityContext:
    runAsNonRoot: true
    runAsUser: 1000
    seccompProfile:
      type: RuntimeDefault
  containers:
  - name: safe-pod
    image: nginx
    securityContext:
      allowPrivilegeEscalation: false
      readOnlyRootFilesystem: true
      capabilities:
        drop: ["ALL"]
    ports:
    - containerPort: 8080
EOF
kubectl get pod safe-pod -n locked-down   # should succeed (nginx may still fail readOnlyRootFS at runtime — that's the point, dig into why)

# Compare: same "safe-pod" spec in default (privileged) namespace works, but in `locked-down` you had to think about every setting
kubectl describe pod safe-pod -n locked-down | grep -A10 Events

# hostPath / hostNetwork abuse demo (should also be blocked under restricted)
kubectl run hostnet --image=nginx -n locked-down --overrides='{"spec":{"hostNetwork":true,"containers":[{"name":"hostnet","image":"nginx"}]}}'

Notes

(fill in your own words after watching + labbing)

📋 Self-Assessment Mastery Checklist (4 Competencies)
🧠 Practice Exam Questions (Module 17 MCQs)
⚡ Take Quiz & Save Progress in Tracker

Review these sample exam questions out loud, test your retrieval, and then unlock official scoring in the interactive tracker.

Question 1: Running as non-root is a:
  • A. Pod/container security best practice
  • B. Requirement to use Services
  • C. Way to bypass NetworkPolicy
  • D. Helm-only feature
✓ Correct Answer: A (Pod/container security best practice)
Option A ('Pod/container security best practice') is the standard production architectural best practice.
Question 2: Pod Security Admission (PSA) can enforce:
  • A. baseline/restricted-style pod security standards
  • B. etcd compaction
  • C. Ingress class names
  • D. StorageClass provisioners
✓ Correct Answer: A (baseline/restricted-style pod security standards)
Option A ('baseline/restricted-style pod security standards') is the standard production architectural best practice.
Question 3: allowPrivilegeEscalation: false helps prevent:
  • A. Gaining more privileges than the parent process
  • B. DNS lookups
  • C. PVC binding
  • D. Service creation
✓ Correct Answer: A (Gaining more privileges than the parent process)
Option A ('Gaining more privileges than the parent process') is the standard production architectural best practice.
Question 4: readOnlyRootFilesystem makes the container root FS:
  • A. Read-only (when supported/configured)
  • B. Encrypted
  • C. Shared across nodes
  • D. Faster always
✓ Correct Answer: A (Read-only (when supported/configured))
Option A ('Read-only (when supported/configured)') is the standard production architectural best practice.
Question 5: seccomp/AppArmor profiles can:
  • A. Restrict syscalls/behaviors of containers
  • B. Replace RBAC
  • C. Provision PVs
  • D. Scale Deployments
✓ Correct Answer: A (Restrict syscalls/behaviors of containers)
Option A ('Restrict syscalls/behaviors of containers') is the standard production architectural best practice.
← Previous Module (16) Cluster Hardening & CIS Benchmarks Next Module (18) → Supply Chain Security & Admission Control