Cloud, DevOps & IT Infrastructure
Certified Kubernetes Security Specialist (CKS): Certification Preparation
by GFU Cyrus AG
- Provider
- GFU Cyrus AG
- Category
- Cloud, DevOps & IT Infrastructure
- Duration
- 1–3 Monate
- Schedule
- Vollzeit
- Locations
- Köln
- Next start
- 2026-09-06T22:00:00+00:00
Course overview
Day 1: Domain 1 - Cluster Setup (15%) and Domain 2 - Cluster Hardening (15%) 1. Cluster Setup: Secure Cluster Components CIS Kubernetes Benchmark with kube-bench: auditing kube-apiserver, etcd, kubelet, CoreDNS, scheduler, controller-manager. TLS configuration for API server, kubelet, and etcd; certificate lifecycle and rotation. Ingress security: TLS termination, secure annotations, protection against common misconfigurations. Protect node metadata and cloud provider endpoints (AWS IMDSv2, Azure IMDS, GCP Metadata). Minimize or avoid Kubernetes Dashboard and GUI access. Verify platform binaries (hashes, signatures). Network Policies with Default-Deny as cluster baseline. Practical exercise:   Execute kube-bench audit on a sample cluster, fix three critical findings (TLS configuration, audit logging, disable anonymous auth); implement Default-Deny Network Policy for a namespace. 2. Cluster Hardening: API Security and RBAC Restrict access to the Kubernetes API: disable anonymous auth, secure authentication methods. Role-Based Access Control (RBAC): Roles, ClusterRoles, RoleBindings, ClusterRoleBindings; least-privilege patterns. Service Accounts: disable automatic token mountings, secure token usage with audience-bound tokens. Regularly update Kubernetes: kubeadm upgrade strategy, node drain, skip versions, security releases. etcd encryption at rest: EncryptionConfiguration, KMS provider, key rotation. Practical exercise:   Design RBAC for a multi-team cluster with two service accounts, least-privilege policy; enable etcd encryption at rest and verify with an encrypted sample secret. Day 2: Domain 3 - System Hardening (10%) and Domain 4 - Minimize Microservice Vulnerabilities (20%) 3. System Hardening: Host OS and Kernel Reduce host OS attack surface: minimal distributions (Bottlerocket, Talos, Flatcar), remove unnecessary packages, automatic security updates. Minimize IAM roles for cloud workers: pod-bound identities (IRSA, Workload Identity), avoid node IAM inheritance. Minimize external network access: security groups, NACLs, bastion concepts for cluster operations. Kernel hardening tools: AppArmor and seccomp profiles for pods, example profiles (RuntimeDefault, Localhost), profile distribution on nodes. Linux capabilities: capabilities drop, fine-grained privilege reduction in containers. Practical exercise:   Harden a pod manifest: seccomp RuntimeDefault, AppArmor profile, capabilities drop to "all" with targeted additions, runAsNonRoot, readOnlyRootFilesystem. 4. Minimize Microservice Vulnerabilities: PSA, OPA, Kyverno, and Sandboxing Pod Security Admission (PSA) and Pod Security Standards (Privileged, Baseline, Restricted): namespace labeling, enforce/audit/warn modes. Migration from Pod Security Policies (PSP, removed in K8s 1.25) to PSA and policy engines. Open Policy Agent (OPA) Gatekeeper and Kyverno as policy engines: constraint templates, policies, validating admission policy. Security contexts at pod and container lev…
Upcoming dates
- 2026-09-06T22:00:00.000Z · 2026-09-09T22:00:00.000Z · Köln · Seminar
- 2026-09-06T22:00:00.000Z · 2026-09-09T22:00:00.000Z · Online-Seminar
- 2027-02-21T23:00:00.000Z · 2027-02-24T23:00:00.000Z · Köln · Seminar
- 2027-02-21T23:00:00.000Z · 2027-02-24T23:00:00.000Z · Online-Seminar
Funding
Bildungsgutschein funding depends on the course details and the decision of the responsible authority.
Data last synced: 2026-08-04