k8s-security.pro
Interactive Audit Tool

Kubernetes Security Audit Checklist

50 security controls across 9 domains. Check off items as you audit your cluster. Progress is saved automatically.

Progress 0 / 50 completed

I. Pod Security

Prevent container breakouts and limit blast radius
1. Enforce Read-Only Root Filesystem High

Ensure readOnlyRootFilesystem: true in SecurityContext.

2. Drop All Capabilities Critical

Explicitly set capabilities: { drop: ["ALL"] }.

3. Prevent Privilege Escalation Critical

Set allowPrivilegeEscalation: false.

4. Run as Non-Root Critical

Enforce runAsNonRoot: true and specify a high UID.

5. Restrict Seccomp Profiles High

Enable RuntimeDefault or custom seccomp profiles.

6. Disable Automount Service Account Token High

Set automountServiceAccountToken: false.

7. Use Ephemeral Storage Limits Medium

Define limits for ephemeral-storage.

II. Network Security

Assume the network is hostile. Isolate everything.
8. Default Deny Policy Critical

Apply a Default Deny All NetworkPolicy.

9. Isolate Namespaces High

Ensure traffic cannot flow between namespaces.

10. Restrict Egress Traffic High

Whitelist only necessary external domains.

11. Encrypt Traffic (mTLS) Medium

Unlock this check with the full product.

12. Secure Ingress High

Unlock this check with the full product.

13. Disable Cloud Metadata Access Critical

Unlock this check with the full product.

III. RBAC & Identity

Least privilege access control
14. Audit ClusterRoles Critical

Unlock this check with the full product.

15. Minimize Wildcards High

Unlock this check with the full product.

16. Service Account Segregation Medium

Unlock this check with the full product.

17. Restrict Escalate & Bind Critical

Unlock this check with the full product.

18. Rotate Kubeconfig Credentials Medium

Unlock this check with the full product.

IV. Cluster Hardening

Governance and admission control
19. Enable Audit Logging High

Unlock this check with the full product.

20. Restrict API Server Access Critical

Unlock this check with the full product.

21. Etcd Encryption High

Unlock this check with the full product.

22. CIS Benchmark Compliance Medium

Unlock this check with the full product.

23. Image Vulnerability Scanning High

Unlock this check with the full product.

24. Admission Controllers High

Unlock this check with the full product.

25. Use Pod Security Standards (PSS) High

Unlock this check with the full product.

V. Supply Chain Security

Secure the software delivery pipeline
26. Sign Images Medium

Unlock this check with the full product.

27. Minimal Base Images Low

Unlock this check with the full product.

28. Pin Image Versions Medium

Unlock this check with the full product.

29. Private Registry Low

Unlock this check with the full product.

VI. Secrets Management

Protect sensitive data at rest and in transit
30. No Secrets in Env Vars High

Unlock this check with the full product.

31. Encrypt Secrets at Rest Critical

Unlock this check with the full product.

32. External Secret Store High

Unlock this check with the full product.

33. Rotate Secrets Regularly Medium

Unlock this check with the full product.

34. GitOps Secret Encryption Critical

Unlock this check with the full product.

VII. Logging & Runtime Security

Detect and respond to active threats
35. Centralized Logging High

Unlock this check with the full product.

36. Audit Logs Enabled Critical

Unlock this check with the full product.

37. Runtime Security Tool High

Unlock this check with the full product.

38. Monitor Resource Usage Medium

Unlock this check with the full product.

39. Alert on Shell Access Medium

Unlock this check with the full product.

40. Container Image Runtime Scanning Medium

Unlock this check with the full product.

VIII. Disaster Recovery

Prepare for the worst-case scenario
41. Etcd Backups Critical

Unlock this check with the full product.

42. Offsite Backups High

Unlock this check with the full product.

43. Restore Drills High

Unlock this check with the full product.

44. Velero Implementation Medium

Unlock this check with the full product.

45. Infrastructure as Code High

Unlock this check with the full product.

IX. API Security

Lock down the Kubernetes API server
46. Disable Anonymous Auth Critical

Unlock this check with the full product.

47. Restrict Anonymous Discovery High

Unlock this check with the full product.

48. NodeRestriction Plugin High

Unlock this check with the full product.

49. Kubelet Security High

Unlock this check with the full product.

50. Dashboard Security High

Unlock this check with the full product.

Unlock All 50 Security Checks

Get the complete checklist with kubectl verification commands, YAML fixes, MITRE ATT&CK references, and CIS Benchmark mappings.