Skip to content
Back to skills

K8s Security Policy

ASecurity

Use when reviewing Kubernetes manifests (Pod, Deployment, StatefulSet, DaemonSet, Job) for security — triggers on "kubernetes security", "securityContext", "pod security", "Pod Security Standards", "harden this manifest", "runAsNonRoot", "readOnlyRootFilesystem", or when YAML for a K8s workload is shown. Produces findings mapped to the Restricted profile plus a corrected manifest.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 1, 2026
ai-agentskubernetesapisecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned October 1, 2026

npx -y skills add matthews-wong/claude-code-plugins --skill k8s-security-policy --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of K8s Security Policy?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for K8s Security Policy
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/matthews-wong-k8s-security-policy/badge)](https://www.skillsdirectory.com/skills/matthews-wong-k8s-security-policy)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: k8s-security-policy
description: 'Use when reviewing Kubernetes manifests (Pod, Deployment, StatefulSet, DaemonSet, Job) for security — triggers on "kubernetes security", "securityContext", "pod security", "Pod Security Standards", "harden this manifest", "runAsNonRoot", "readOnlyRootFilesystem", or when YAML for a K8s workload is shown. Produces findings mapped to the Restricted profile plus a corrected manifest.'
---

# Kubernetes Security Policy Review

Review a Kubernetes workload manifest against the **Pod Security Standards (Restricted profile)** and adjacent hardening controls. Anchor every finding to the actual YAML shown.

## Method

1. **Identify the workload(s).** Find the Pod template (`spec.template.spec` for controllers, or `spec` for a bare Pod) and each container/initContainer.
2. **Evaluate controls** using `reference/controls.md`. For each control mark PASS / FAIL / MISSING with the path (e.g. `spec.containers[0].securityContext.runAsNonRoot`). Absence of a field is usually a FAIL — defaults are insecure.
3. **Report findings**: table of Severity | Control | Path | Current | Required.
4. **Emit a corrected manifest** (or patch) applying the pod-level and container-level `securityContext`, resource limits, and any structural fixes.
5. **Recommend enforcement**: namespace Pod Security Admission labels and/or an admission policy engine — see `reference/controls.md`.

## Core controls (Restricted profile essentials)

Set at **pod level** (`spec.securityContext`) and/or **container level** (`spec.containers[*].securityContext`):

- `runAsNonRoot: true` and an explicit non-zero `runAsUser` / `runAsGroup`.
- `allowPrivilegeEscalation: false` (container level).
- `privileged: false` (never true).
- `capabilities.drop: ["ALL"]`; add back only specific caps if genuinely required (e.g. `NET_BIND_SERVICE`).
- `readOnlyRootFilesystem: true` (mount an `emptyDir` for writable paths).
- `seccompProfile.type: RuntimeDefault` (pod or container level).

Adjacent must-haves:

- **Resource requests AND limits** for cpu and memory on every container (prevents noisy-neighbor DoS and eviction surprises).
- **No host namespaces**: `hostNetwork`, `hostPID`, `hostIPC` all false/absent.
- **No `hostPath` volumes** (or tightly restricted, read-only if unavoidable).
- **No `hostPort`.**
- **Do not auto-mount the service account token** unless the workload calls the K8s API (`automountServiceAccountToken: false`).
- **Pinned image + digest**, never `:latest`; set `imagePullPolicy` appropriately.
- **Liveness & readiness probes** defined.
- Drop unneeded `NET_RAW`; avoid `sysctls` unless required.

## Output

Findings table + corrected manifest + enforcement recommendation. Do not fabricate cluster state, CVEs, or scanner output — recommend `kubectl`, `kube-score`, `kubeconform`, Trivy, Checkov, or Polaris for automated checks.

## References

- `reference/controls.md` — full control list with paths, why, and Pod Security Admission enforcement.
- `reference/example.md` — an insecure manifest and its hardened rewrite.

Files in this skill

  • SKILL.md3 KB
  • reference/controls.md3.9 KB
  • reference/example.md2.3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…