Memory hook: The node owns the kernel; the Pod shares a network; access to either changes the blast radius.
Must remember
The kubelet manages assigned Pods on a node and talks to the runtime through CRI. Protect its HTTPS API with authentication and authorization, restrict network access and avoid anonymous or obsolete unauthenticated endpoints. A user who can reach a powerful kubelet endpoint may bypass protections assumed at the normal API entry point.
The container runtime starts containers and interacts closely with the host. Keep runtime and host packages patched, minimize installed services and tightly protect runtime sockets. Mounting a container-management socket into an application can expose powerful host operations; it is not just another harmless file mount.
A Pod is the scheduling unit. Its containers share a network namespace/IP and can talk over localhost; they can share configured volumes. This makes a sidecar part of the workload's trust boundary. Processes are not automatically placed into one shared PID namespace unless configured. Privileged mode, host PID/network namespaces and writable hostPath mounts can erode isolation and expose node resources.
Kube-proxy implements Service forwarding behavior on nodes in common cluster designs. Some network implementations replace that function. It is neither the container runtime nor the mechanism that automatically enforces every NetworkPolicy. CNI integration supplies Pod networking; policy enforcement depends on a capable implementation. Protect network agents because they often need elevated host access. DNS resolution, Service selection and policy enforcement are separate steps.
Storage security includes both API permission and access to the actual backend. A PVC requests storage; a PV represents it; CSI drivers connect Kubernetes to storage systems. Apply filesystem permissions, appropriate mount settings, backend authorization and encryption in transit/at rest as supported. A PVC access mode describes mount capability, not an authorization policy: ReadWriteOnce does not mean only one person or Pod can read the data.
Persistent data and snapshots may outlive a Pod. Reclaim policy Retain leaves backing storage for managed reuse or cleanup; Delete can remove the backing asset depending on the provisioner. Backups need their own access, retention and recovery controls. Avoid placing confidential data on broadly accessible hostPath volumes and understand which administrators can access node disks.
Resource boundaries also protect availability. Requests guide scheduling; limits constrain supported resource consumption. ResourceQuota limits aggregate namespace consumption and object counts; LimitRange can supply/enforce per-object resource rules. CPU throttling and memory termination are different outcomes. Limits reduce noisy-neighbor risk but do not replace application rate limiting or denial-of-service protection.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Prevent a workload controlling the host runtime | Do not expose runtime sockets; restrict host mounts and privileges. |
| Restrict lateral Pod traffic | Use a policy-capable network implementation and NetworkPolicies. |
| Protect data after a Pod is deleted | Manage the PV/backend, snapshots, permissions and encryption independently of Pod lifetime. |
| Prevent a namespace consuming every resource | Use quotas and suitable workload limits, preserving legitimate capacity. |
Traps
- Containers inside one Pod are not mutually isolated network tenants.
- RWO is a storage attachment/access capability, not a data confidentiality control.
- An authenticated Kubernetes API does not secure an independently exposed kubelet API.
- Deleting a Pod does not reliably delete its persistent data or snapshots.
Active recall
1. Which local endpoint should not be mounted into an untrusted application for convenience?
The container-runtime management socket. Its operations can grant extensive control over containers and the host.
2. Do two containers in a Pod need a Service to talk over localhost?
No. They share the Pod network namespace and can use localhost directly.
3. Does kube-proxy guarantee enforcement of NetworkPolicies?
No. NetworkPolicy enforcement depends on the network implementation; Service forwarding is a different responsibility.
4. Does a ReadWriteOnce PVC guarantee one Pod can read it?
No. It normally permits read-write attachment from one node; multiple Pods there may use it. Permissions and workload isolation remain necessary.
5. What survives deletion of a Pod using a PVC?
The claim and persistent backing storage can remain, as can independent snapshots/backups. Lifecycle policy must address each asset.