Memory hook: Cloud contains cluster; cluster contains containers; containers execute code.
Must remember
Security follows the 4Cs: Cloud, Cluster, Container, Code. Each inner layer depends on outer layers, so a patched application cannot compensate for a stolen cloud administrator credential. Apply several independent controls: reduce the chance of compromise, limit its reach, detect it and recover.
| Layer | What to protect | Typical control |
|---|---|---|
| Cloud/infrastructure | Account, network, machines, metadata endpoints and physical platform | IAM, private networking, host patching and provider controls |
| Cluster | API, identities, control plane, nodes and configuration | RBAC, admission, audit and upgrades |
| Container | Image, runtime, privileges and resource use | Scan/sign images, non-root execution and constrained runtime |
| Code | Application input, dependencies, authorization and credentials | Reviews, tests, dependency updates and secret hygiene |
Shared responsibility changes with the service. A provider may operate a managed control plane; the customer still owns application data, workload configuration and granted permissions. Check who operates worker nodes, patches each layer, holds encryption keys and retains logs. Managed Kubernetes does not automatically make a public application private.
The CIA triad asks whether data stays confidential, changes are trustworthy and service remains available. Least privilege restricts each identity to required actions and duration. Zero trust verifies identity and authorization even for internal traffic; network location alone is not identity.
Preventive controls stop or constrain an action, such as admission rejecting privileged Pods. Detective controls reveal it, such as an alert on unexpected API access. Corrective controls restore a safe state, such as revoking a leaked credential and redeploying a clean workload. Administrative controls include training and approved procedures; technical controls implement system behavior; physical controls protect facilities and equipment.
Linux namespaces separate views of processes, mounts or networks; cgroups account for and constrain resources. These are different from Kubernetes namespaces, which organize API objects. Containers usually share a host kernel; they are not equivalent to virtual machines. Stronger isolation may require sandboxed runtimes, dedicated nodes or separate clusters according to the trust model.
Application controls remain necessary: validate untrusted input, parameterize database queries, enforce authorization for each request and avoid hard-coded credentials. SAST examines source; DAST exercises a running application; dependency analysis identifies risky third-party components. None guarantees absence of defects.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Protect against a stolen cloud identity | Constrain cloud IAM and credentials; container settings cannot protect the provider account. |
| Detect an unexpected permission change | Record and alert on API audit events; a preventive control alone does not establish what happened. |
| Run mutually hostile tenants | Assess stronger runtime or cluster isolation, with identity and network controls at every boundary. |
Traps
- A Kubernetes namespace is neither a VM nor an automatic firewall.
- Provider-managed infrastructure does not transfer responsibility for application authorization.
- Zero trust does not mean every request is denied; it means trust is explicitly established and bounded.
Active recall
1. An application is patched but its node credentials are stolen. Which layer remains exposed?
The infrastructure/node and identity layers. Application patching does not revoke credentials or remove their permissions.
2. Which mechanism limits a process group's CPU and memory use?
Cgroups. Linux namespaces chiefly separate views of system resources.
3. Is an alert on a newly privileged Pod preventive or detective?
Detective. An admission rule rejecting that Pod is preventive.
4. Who normally owns an application's data and RBAC grants on managed Kubernetes?
The customer, unless an explicit service agreement assigns a particular responsibility elsewhere.
5. Why keep application authorization when the network is private?
A private network can contain compromised or overprivileged identities. Each application request still needs an authorization decision.