Identity and security
Hardening
37 / 69

Harden four layers: node, control plane, workload and network.

Each item is cheap on day one and painful to retrofit.

Node
✓IMDSv2 required, hop limit 1
✓Bottlerocket or hardened AMI
✓Minimal node IAM role
✓Patch by rolling nodes often
Control plane
✓Restricted or private endpoint
✓Access entries, API auth mode
✓Audit logs enabled
✓KMS key for Secrets
Workload
✓Pod Identity per ServiceAccount
✓Pod Security Standards enforced
✓Non-root, read-only filesystem
✓Requests, limits, PDBs
Network
✓Default-deny NetworkPolicy
✓Security groups for sensitive Pods
✓Private subnets, VPC endpoints
✓WAF on public ALBs
namespace Pod Security enforcement
kubectl label namespace shop pod-security.kubernetes.io/enforce=restricted pod-security.kubernetes.io/warn=restricted

Ship the checklist as code: Terraform for the cluster settings, policies for admission, and a CI check that fails when a box is unticked.