Skip to content

Runbook 02 — Enterprise Kubernetes Environment Assessment

Item Details
Runbook ID K8S-RB-02
Category Enterprise Security Assessment
Difficulty Advanced
Estimated Time 2–4 Hours
Environment Amazon EKS / Azure AKS / Google GKE / On-Prem Kubernetes
Platform Enterprise Kubernetes
Primary Role Kubernetes Security Engineer
Team Cloud Security
Escalation Cloud Security Architect / Platform Engineering

CloudNova Technologies has recently completed the deployment of a new enterprise Kubernetes platform.

Before the environment is approved for production workloads, the Cloud Security Team must perform a comprehensive security and operational assessment to ensure that the cluster aligns with organisational standards, security policies, and industry best practices.

You have been assigned to conduct the assessment and provide recommendations before production approval.


Validate the Kubernetes environment across the following domains:

  • Cluster Architecture
  • Identity & Access Management
  • Node Security
  • Workload Security
  • Networking
  • Storage
  • Secrets Management
  • Monitoring & Logging
  • Backup & Disaster Recovery
  • Governance & Compliance
  • Operational Readiness

The assessment is successful when:

  • Security controls are implemented appropriately.
  • No Critical findings remain unresolved.
  • High-risk issues have mitigation plans.
  • Compliance requirements are satisfied.
  • Platform governance is documented.
  • Operational monitoring is functional.

Cluster Overview
Platform Architecture
Identity & RBAC
Node Security
Workload Security
Networking
Storage
Monitoring
Compliance
Assessment Report

Collect general platform information.

Terminal window
kubectl cluster-info
kubectl version
kubectl get nodes -o wide

Document:

  • Cluster Name
  • Kubernetes Version
  • Cloud Provider
  • Number of Control Plane Nodes
  • Number of Worker Nodes
  • Kubernetes Distribution
  • Container Runtime

Assessment Phase 2 — Cluster Architecture

Section titled “Assessment Phase 2 — Cluster Architecture”

Review:

Terminal window
kubectl get nodes
kubectl describe nodes

Verify:

  • Multi-node deployment
  • Worker node separation
  • Control Plane isolation
  • Availability Zones
  • Private networking
  • Cluster scaling capability

Control Status
HA Architecture
Multi-AZ
Private Nodes
Separate Workloads
Cluster Scaling

Assessment Phase 3 — Namespace Governance

Section titled “Assessment Phase 3 — Namespace Governance”

Review:

Terminal window
kubectl get namespaces --show-labels

Confirm:

  • Naming standards
  • Environment labels
  • Owner labels
  • Business Unit labels
  • Pod Security labels

Example:

production
development
testing
security
monitoring

Assessment Phase 4 — Identity & Access Management

Section titled “Assessment Phase 4 — Identity & Access Management”

Review Service Accounts.

Terminal window
kubectl get sa -A

Review ClusterRoles.

Terminal window
kubectl get clusterroles

Review RoleBindings.

Terminal window
kubectl get rolebindings -A
kubectl get clusterrolebindings

Review Current Permissions.

Terminal window
kubectl auth can-i --list

Validate:

  • Least Privilege
  • Dedicated Service Accounts
  • No unnecessary ClusterAdmin access
  • Separation of Duties

Inspect Worker Nodes.

Terminal window
kubectl describe node <NODE>

Review:

  • Runtime
  • Labels
  • Taints
  • Allocatable Resources
  • Node Conditions

Security Checks

Confirm:

  • No privileged SSH access
  • Managed patching
  • Node image management
  • Secure bootstrap
  • Runtime updates

Review Deployments.

Terminal window
kubectl get deployments -A

Inspect one Deployment.

Terminal window
kubectl describe deployment <DEPLOYMENT>

Validate:

  • Security Context
  • Non-root execution
  • Resource Limits
  • Health Probes
  • Dedicated Service Accounts
  • Read-only Filesystem
  • Dropped Capabilities

Review Pods.

Terminal window
kubectl get pods -A

Look for:

Privileged Containers
Host Network
Host PID
Host IPC
HostPath
Root User

Review Secrets.

Terminal window
kubectl get secrets -A

Validate:

  • Secrets exist only where required.
  • No plaintext credentials.
  • Encryption enabled.
  • Secret rotation process documented.
  • External Secret Manager implemented.

Examples:

  • AWS Secrets Manager
  • Azure Key Vault
  • Google Secret Manager
  • HashiCorp Vault

Review:

Terminal window
kubectl get configmaps -A

Confirm:

  • Configuration separated from code.
  • No passwords inside ConfigMaps.
  • Environment-specific configuration.

Review Storage Classes.

Terminal window
kubectl get storageclass

Review PVs.

Terminal window
kubectl get pv

Review PVCs.

Terminal window
kubectl get pvc -A

Validate:

  • Encryption
  • Dynamic Provisioning
  • Backup
  • Recovery
  • Access Modes

Review Services.

Terminal window
kubectl get svc -A

Review Network Policies.

Terminal window
kubectl get networkpolicy -A

Confirm:

  • Default Deny
  • East-West segmentation
  • Internal Services
  • Public Exposure reviewed

Review Ingress.

Terminal window
kubectl get ingress -A

Validate:

  • TLS
  • WAF
  • Public endpoints
  • Approved Domains

Assessment Phase 11 — Monitoring & Logging

Section titled “Assessment Phase 11 — Monitoring & Logging”

Review:

Terminal window
kubectl get pods -n kube-system

Confirm:

  • Metrics Server
  • CoreDNS
  • kube-proxy

Review enterprise tooling.

Examples:

  • Prometheus
  • Grafana
  • Loki
  • Fluent Bit
  • Fluentd
  • OpenTelemetry

Cloud-native examples:

  • Amazon CloudWatch
  • Azure Monitor
  • Google Cloud Operations

Confirm Kubernetes Audit Logging.

Review:

  • API Activity
  • Authentication
  • RBAC Changes
  • Secret Access
  • Administrative Actions

Cloud integrations:

  • AWS CloudTrail
  • Azure Activity Logs
  • Google Cloud Audit Logs

Assessment Phase 13 — Backup & Disaster Recovery

Section titled “Assessment Phase 13 — Backup & Disaster Recovery”

Confirm:

  • etcd Backup
  • Persistent Volume Backup
  • Cluster Recovery Procedure
  • Restore Testing
  • Cross-Region Backup

Cloud examples:

  • AWS Backup
  • Azure Backup
  • Google Backup

Review alignment with:

  • CIS Kubernetes Benchmark
  • CIS Cloud Benchmark
  • NIST CSF
  • ISO 27001
  • SOC 2
  • PCI DSS
  • HIPAA

Confirm:

  • Policies documented
  • Security controls implemented
  • Exceptions approved

Assessment Phase 15 — Operational Readiness

Section titled “Assessment Phase 15 — Operational Readiness”

Confirm:

  • Monitoring
  • Alerting
  • Incident Response
  • Runbooks
  • Change Management
  • Capacity Planning
  • Platform Ownership

Domain Status
Architecture
IAM
RBAC
Workloads
Storage
Networking
Secrets
Monitoring
Logging
Backup
Compliance
Operations

Examples

  • Public API Server
  • Unencrypted Secrets
  • ClusterAdmin granted broadly
  • No backups
  • etcd exposed

Immediate remediation required.


Examples

  • Missing Network Policies
  • Containers running as root
  • Privileged Pods
  • Public LoadBalancers

Examples

  • Missing labels
  • Missing health probes
  • High resource utilisation
  • Old Kubernetes version

Examples

  • Documentation gaps
  • Minor warnings
  • Unused ConfigMaps
  • Legacy ReplicaSets

Prioritise improvements in the following order:

  1. Identity & Least Privilege
  2. Secrets Protection
  3. Network Segmentation
  4. Runtime Security
  5. Backup & Recovery
  6. Monitoring & Alerting
  7. Governance
  8. Compliance Automation

Environment Name:
Assessment Date:
Assessor:
Cloud Provider:
Kubernetes Version:
Overall Status:
Architecture:
Identity:
RBAC:
Networking:
Storage:
Secrets:
Monitoring:
Logging:
Compliance:
Operational Readiness:
Critical Findings:
High Findings:
Medium Findings:
Recommendations:
Production Approval:
Approved / Conditionally Approved / Rejected

Always ensure:

  • Private Worker Nodes
  • Least Privilege RBAC
  • Dedicated Service Accounts
  • Network Policies
  • Encrypted Storage
  • External Secrets Management
  • Continuous Monitoring
  • Backup Validation
  • Compliance Reviews
  • Security Assessments before production deployment

Issue Investigation
Worker Node NotReady kubectl describe node
CrashLoopBackOff kubectl logs
Pending Pods Scheduler & Events
Storage Pending PVC
DNS Issues CoreDNS
Network Issues Services & NetworkPolicies
Secret Errors Secret Mounts
Permission Errors RBAC

Collect evidence for:

  • Cluster Information
  • Node Health
  • Namespaces
  • Service Accounts
  • RBAC
  • Workload Security
  • Storage
  • Network Policies
  • Ingress
  • Monitoring
  • Logging
  • Backup
  • Compliance Controls
  • Risk Assessment
  • Final Report

This runbook provides a structured methodology for performing a comprehensive enterprise Kubernetes environment assessment.

By following this procedure, Cloud Security Engineers can validate architecture, identity, networking, workload security, storage, monitoring, compliance, and operational readiness before approving a Kubernetes environment for production use. The outcome is a documented assessment with risk ratings, remediation recommendations, and a clear production readiness decision.