k8s-security.pro
kubectl audit cluster --against=cis,mitre,nist

Kubernetes Production
Security Checklist

The 50-Point Master Audit, 20+ Ready-to-Use YAML Templates, and Implementation Guides for Production Clusters.

50-Point Audit

Proven, actionable checklist across 9 security domains.

25 YAML Templates

Copy-paste security templates for instant deployment.

30-Min Deploy

From zero to secured cluster in under 30 minutes.

View Pricing Plans

See What's Inside

Production-tested security configurations you can deploy immediately.

Sample YAML Template
# Template 01: Default Deny NetworkPolicy
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: default-deny-all
  labels:
    app.kubernetes.io/part-of: k8s-security-pro
spec:
  podSelector: {}
  policyTypes:
    - Ingress
    - Egress
Checklist Preview

Enforce Pod Security Standards

CRITICAL -- Apply restricted PSS at namespace level

Apply Default-Deny NetworkPolicies

HIGH -- Block all traffic, then whitelist explicitly

Implement Least-Privilege RBAC

CRITICAL -- No wildcard verbs or resources in Roles

Enable Audit Logging

HIGH -- Log all write operations at RequestResponse level

+ 46 more checks across 9 security domains...

Choose Your Plan

Every tier includes a 30-day money-back guarantee.

Starter

Everything you need to audit and secure your cluster.

$59 USD
  • 50-Point Master Audit Checklist
  • 25 Production YAML Templates
  • Quick Start Implementation Guide
  • Printable Checklist (PDF-ready)
Get Starter
Most Popular

Professional

For teams that need enterprise-grade tooling.

$149 USD
  • Everything in Starter
  • Helm Charts (ready to deploy)
  • Kustomize Base + Overlays
  • CIS Benchmark Mapping
  • MITRE ATT&CK References
  • 1 year of content updates
Get Professional

Enterprise

Full compliance coverage and priority support.

$199 USD
  • Everything in Professional
  • SOC2 & CIS Benchmark Compliance Mapping
  • CI/CD Security Pipeline Templates (GitHub Actions + GitLab CI)
  • Editable source + organization-wide commercial license
  • Priority Email Support
Get Enterprise

Team License

Save 20%

5-seat Professional bundle for engineering teams.

  • 5x Professional tier access
  • Helm Charts + Kustomize + CIS/MITRE
  • Single purchase, shared license

30-day money-back guarantee

Instant download after checkout via Polar. Every check maps to a public standard (CIS, MITRE ATT&CK, NIST) so you can verify it yourself.

Verifiable, not hand-wavy

Every recommendation maps to a public security standard, so you can check the reasoning yourself instead of taking our word for it.

50
Audit checks across 9 domains
20+
Production-ready YAML templates
CIS · MITRE · NIST
Public standards every check maps to
SA

Built & maintained by Seyit Han Alkan

A software engineer who distilled the CIS Kubernetes Benchmark, MITRE ATT&CK for Containers, and NIST SP 800-190 into a copy-paste hardening kit — so you skip the weeks of cross-referencing.

Get the Free K8s Security Quick-Start Kit

Get 5 essential templates + audit checklist highlights delivered to your inbox.

No spam. Unsubscribe anytime.

Frequently Asked Questions

What Kubernetes versions are supported?
All templates and checks are designed for Kubernetes 1.25 and above. This covers Pod Security Standards (which replaced PodSecurityPolicy), modern RBAC features, and current API versions. Most checks are also applicable to managed services like EKS, GKE, and AKS.
Do I need to install anything?
No special tooling required. You just need kubectl access to your cluster. The YAML templates can be applied directly with kubectl apply -f. The Professional tier also includes Helm charts if you prefer that workflow.
What's the difference between the tiers?
Starter gives you the complete checklist and all 25 YAML templates -- perfect for individual engineers. Professional adds Helm charts, Kustomize overlays, and compliance framework references (CIS Benchmarks, MITRE ATT&CK) for teams standardizing on security. Enterprise includes everything plus SOC2 & CIS compliance mapping, CI/CD pipeline templates (GitHub Actions + GitLab CI), editable source with an organization-wide commercial license, and priority email support.
Is there a money-back guarantee?
Yes. All plans come with a 30-day money-back guarantee. If the checklist and templates don't improve your cluster security, we'll refund your purchase -- no questions asked.
Can I use this for multiple clusters?
Yes. Your purchase covers unlimited clusters within your organization. The templates are designed to be reusable across development, staging, and production environments.
Do you offer team licenses?
Yes. For teams of 5 or more, contact us at support@k8s-security.pro for volume pricing. Enterprise tier customers automatically get team license terms included.

Built on Industry Standards

Every check and template is mapped to real-world security frameworks used by enterprises worldwide.

CIS Benchmarks

Aligned with CIS Kubernetes Benchmark v1.8 for hardening best practices.

MITRE ATT&CK

Mapped to MITRE ATT&CK for Containers threat matrix techniques.

NIST SP 800-190

Follows NIST container security guidelines and risk assessment framework.

Secure Your Clusters Today

Harden your Kubernetes clusters with a 50-point checklist and 20+ templates mapped to CIS, MITRE ATT&CK, and NIST SP 800-190.

Get Started

30-day money-back guarantee. Instant download via Polar.