certslothcertsloth
CKS/Topic 03

CNCF / Specialist

Cluster Exposure, Benchmarks and Trust

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Close unnecessary paths before trusting the workload.

Must remember

Restrict API-server, kubelet and etcd access to intended clients. Authenticate and authorize control-plane operations; protect certificates, kubeconfigs and encryption keys. A public IP is not the only exposure: a compromised Pod may reach internal administrative endpoints or node metadata if paths are unrestricted.

Use the appropriate CIS benchmark and a tool such as kube-bench to review settings, then understand each finding before changing it. Benchmark versions and managed-provider responsibilities matter. A control marked manual or not applicable is not automatically a failure; document the rationale and verify the real risk.

Protect cloud instance metadata through provider-supported mechanisms and workload network controls. Prefer workload-scoped identity over inheriting broad node privileges. NetworkPolicy enforcement depends on the CNI, and host-network/metadata paths require explicit platform analysis. Test permitted and denied flows, including DNS and required control-plane access.

Ingress TLS needs a matching host/certificate, protected private key and a controller that actually terminates or passes through TLS as intended. TLS at the edge does not automatically encrypt every backend hop. Verify downloaded platform binaries using trusted checksums/signatures from authenticated distribution sources, not a checksum fetched from the same untrusted mirror.

Patch through supported upgrades with compatibility checks, backups and controlled disruption. Hardening that breaks quorum or locks out authorized recovery can reduce availability without delivering the intended security benefit.

Choose under exam pressure

Requirement Choice and reason
Unexpected node credentials available to a Pod Inspect metadata reachability and workload identity design.
Benchmark finding Validate version, applicability and component ownership before remediation.
Downloaded cluster binary Verify trusted origin and integrity before installation.

Traps

  • A passed benchmark is not proof against every attack.
  • An edge HTTPS padlock says nothing about all internal hops.

Active recall

1. Why protect etcd?

It contains sensitive cluster state, potentially including Secrets.

2. Why match benchmark version?

Expected settings and supported controls vary across Kubernetes/platform versions.

3. Why isolate metadata access?

It may expose privileged instance identity or configuration.

4. What must a TLS test verify?

Hostname/certificate trust and the actual termination/encryption path.

5. Why preserve recovery access?

A security change should not prevent authorized incident recovery.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.