Container and Kubernetes Security Questions
Securing containerized and orchestrated workloads. Covers container image scanning and hardening, Kubernetes security (RBAC, network policies, pod security, secrets), runtime protection, and cloud-native security patterns. The specific attack surface and controls introduced by containers and orchestration platforms.
List core container security practices you would apply before allowing images to be deployed to production. Cover at least image scanning, vulnerability management, running containers as non-root, immutable images, supply-chain verification, and runtime defenses. Briefly explain the operational process for each practice.
Given a production Kubernetes cluster accessed by multiple teams, describe concrete controls you would implement to restrict and harden access to the Kubernetes API server and cluster resources. Cover authentication (OIDC, client certificates), authorization (RBAC, least privilege), network-level access, audit logging, and developer workflows for requesting elevated access.
Design a runtime security posture for Kubernetes: include admission controls (OPA/Gatekeeper), Pod Security Standards, seccomp and AppArmor profiles, eBPF-based detection tools (e.g., Falco), image provenance/signing (e.g., Sigstore), and an incident response plan for suspected container escapes. Explain how these controls work together and their operational implications.
Create an operational plan to detect, prioritize, and remediate container image vulnerabilities across CI and runtime clusters. Cover scanning cadence, integrating scanners in CI (blocking vs advisory), SBOM generation, automated rebuilds/patching, exception management, prioritization by CVSS and exploitability, and communication to product/stakeholders.
That is every published Container and Kubernetes Security question for DevOps Engineer so far. Browse the other topics in this category, or practice this one interactively.