Cloud & Kubernetes Security: CSPM & Threat Modeling
Harden multi-tenant cloud and container infrastructure: the MITRE ATT&CK Matrix for Kubernetes, detecting misconfigurations with Cloud Security Posture Management (CSPM), enforcing security guardrails with Validating Admission Controllers (Kyverno / OPA Gatekeeper), and container supply chain security (cosign / SBOMs).
What You Will Learn in This Lesson
- The MITRE ATT&CK Matrix for Kubernetes: Initial Access, Execution, Persistence, Privilege Escalation, and Egress
- Validating Admission Controllers: intercepting Kubernetes API requests before persisting to etcd
- Writing policy-as-code guardrails with Kyverno to disallow root containers and hostPath volume mounts
- Cryptographic container image signing and Software Bill of Materials (SBOM) verification using Sigstore `cosign`
Introduction & Core Concept
Attackers compromising a single pod can access the host root filesystem or the cloud provider instance metadata service if Admission Controllers and CSPM guardrails are not strictly enforced.
Syntax & Structure
apiVersion: kyverno.io/v1kind: ClusterPolicymetadata: name: disallow-root-userspec: validationFailureAction: EnforceKyverno Policy-as-Code Enforcing Non-Root Containers and Disallowing hostPath
yaml1234567891011121314151617181920212223242526272829303132333435363738394041# Kyverno Policy Guardrail: Prevent Privileged Containers & HostPath Volume MountsapiVersion: kyverno.io/v1kind: ClusterPolicymetadata:name: enforce-pod-security-standardsspec:validationFailureAction: Enforce # Rejects non-compliant pods immediately!background: truerules:# Rule 1: Disallow Root User Execution- name: require-run-as-non-rootmatch:any:- resources:kinds:- Podvalidate:message: "Running containers as root (UID 0) is strictly forbidden for security compliance."pattern:spec:securityContext:runAsNonRoot: truecontainers:- securityContext:allowPrivilegeEscalation: falsecapabilities:drop:- ALL# Rule 2: Disallow dangerous hostPath mounts (prevents host filesystem takeover)- name: disallow-host-pathmatch:any:- resources:kinds:- Podvalidate:message: "hostPath volume mounts are prohibited. Use CSI PersistentVolumes."pattern:spec:=(volumes):- X(hostPath): null
Line-by-Line Technical Breakdown
Try It Yourself (Interactive Editor)
Modify the code in real-time and click Run to test live browser output and console logs.
Common Mistakes & How to Avoid Them
#1: Mounting the host Docker socket (`/var/run/docker.sock` or `containerd.sock`) inside application containers.
Mounting the container runtime socket gives container processes direct control over the host daemon, allowing instant root escape.
volumeMounts:
- mountPath: /var/run/docker.sock
name: docker-sock # Instant root host compromise!// Use isolated rootless builders like Kaniko or Buildah without host socket mountsIndustry Best Practices & Professional Standards
- Enforce Kubernetes Pod Security Standards at the `restricted` profile level.
- Deploy Kyverno or OPA Gatekeeper to automate policy-as-code enforcement.
- Sign all production container images using Sigstore `cosign` and generate automated SBOMs.
Lesson Summary & Core Takeaways
- CSPM continuously audits cloud infrastructure against misconfigurations.
- Kubernetes Admission Controllers enforce zero-trust security guardrails before pod creation.
- Disallowing root execution, dropping capabilities, and signing container images harden the cloud supply chain.