Kubernetes

Kubernetes Security and Networking

Harden the cluster and master its networking layer: CIS benchmarks, Cilium, Gateway API traffic management, supply-chain security, and NetworkPolicy - all on your own kind cluster.

Photo from pexels
Duration
5 days
Level
Intermediate to Advanced
Format
On-site
Price
On request

What to expect

Harden the cluster and master its networking layer over five hands-on days: CIS benchmarks, Cilium, Gateway API traffic management, supply-chain security, and NetworkPolicy, all running on your own kind cluster.

What to know before

Who it's for

  • Platform and security engineers who have completed Kubernetes Fundamentals (or have equivalent experience) and now own cluster hardening and network design.
  • Teams who can deploy workloads confidently but still treat networking and security as someone else's problem - or as whatever the default CNI happened to ship with.
  • Each participant works on their own VM with VS Code preinstalled, running a multi-node kind cluster on Docker with Cilium as the CNI - no cloud account needed to attend.

You'll learn to

  • Harden a cluster to CIS benchmark expectations: API server, kubelet, and host OS attack surface.
  • Install and operate Cilium as the cluster CNI, including IPAM, packet-level troubleshooting, and Gateway API traffic management.
  • Design NetworkPolicy, encryption, RBAC, and supply-chain security controls, then verify them with a live incident drill.

Agenda

  1. Day 1

    • CIS benchmarks for Kubernetes clusters
    • API server hardening
    • kubelet security
    • Minimizing host OS attack surface
  2. Day 2

    • Installing and configuring Cilium as the cluster CNI
    • IPAM and Pod CIDR allocation
    • Packet-level troubleshooting with iptables, ip, tcpdump, and cilium status
    • Multi-interface pods and troubleshooting pod-to-pod and DNS connectivity
  3. Day 3

    • kube-proxy vs. CNI alternatives
    • Customizing CoreDNS for services
    • The Gateway API: Gateway and HTTPRoutes
    • Egress gateways for cluster-exit traffic, and cross-cluster service discovery and load balancing
  4. Day 4

    • Pod Security Standards and admission control
    • Image scanning and minimizing microservice vulnerabilities
    • Supply-chain security: image signing and provenance
  5. Day 5

    • NetworkPolicy design with Cilium
    • Node- and pod-level encryption, and TLS certificate management for the Gateway API
    • Pod-level authentication and authorization, RBAC, and Secrets management
    • Network observability (metrics, tracing, log auditing) and an incident drill

The MVJ Method

Lots of practical, hands-on teaching. Theory shows up only when you need it to unblock the next exercise.

  • Mostly hands-on. Most of the session is spent building real labs and real pipelines, not watching slides.

  • Your own cluster, not a shared sandbox. Every participant runs a real multi-node kind cluster on their own VM, so what gets built in the room is what ships on Monday.

  • Small enough that everyone drives. Groups of 4-12, so every attendee gets keyboard time.

  • You keep the runbook. Labs, scripts, and reference material go home with your team as the start of your own documentation, not a one-off slide deck.

Request this training

Tell us a bit about your team and we'll get back to you to schedule Kubernetes Security and Networking.

Manuel Vogel-Johnson

Principal Engineer

Networking and security get bolted on after an incident, not designed in from day one. We spend a full week doing both together, because a NetworkPolicy nobody understands is worse than no NetworkPolicy at all.

Kubernetes Security and Networking

Harden the cluster and master its networking layer: CIS benchmarks, Cilium, Gateway API traffic management, supply-chain security, and NetworkPolicy - all on your own kind cluster.

Duration
5 days
Format
On-site
Level
Intermediate to Advanced
Price
On request

Learning goals

  • Harden a cluster to CIS benchmark expectations: API server, kubelet, and host OS attack surface.
  • Install and operate Cilium as the cluster CNI, including IPAM, packet-level troubleshooting, and Gateway API traffic management.
  • Design NetworkPolicy, encryption, RBAC, and supply-chain security controls, then verify them with a live incident drill.

FAQs

Related trainings

Kubernetes5 daysBeginner to IntermediateOn-siteOn request

Kubernetes Foundations

Go from container basics to a production-shaped Kubernetes cluster: architecture, workloads, networking, storage, troubleshooting, and observability - all on your own kind cluster.

Kubernetes4 daysIntermediateOn-siteOn request

Kubernetes on AWS

Run production workloads on EKS: networking, autoscaling, GitOps deployment, and the operational habits that keep clusters calm.

Kubernetes5 daysIntermediateOn-siteOn request

Kubernetes Operations

Run and ship on a cluster you maintain yourself: kubeadm upgrades, etcd backup and restore, GitOps with ArgoCD or Flux, and progressive delivery - all on your own kind cluster.