CKS (Certified Kubernetes Security Specialist)
Hardening, supply chain, runtime and audit.
40 published guides
32 of 40 guides need path access. Unlock CKS path
40-guide Certified Kubernetes Security Specialist learning path · 40 published · about 668 min of reading · 9 learning tracks · reviewed 25 August 2026
Orientation3 guides
What CKS asks, why a valid CKA is a prerequisite, and the clusters used.
-
Concepts 12 min
CKS Exam Format and Domain Weights
Six domains, two hours of tasks, 67% - and a CKA you must already hold.
All six domainsUpdated 25 Aug 2026
-
Concepts 11 min
Moving from KCSA to CKS
Twenty terms counted across both banks, and the four where CKS is on ground KCSA never walks.
All six domainsUpdated 25 Aug 2026
-
Hands-on Lab 14 min
The CKS Practice Clusters
Three clusters, one of them deliberately untainted - and an encryption setting that is a task rather than a fact.
All six domainsUpdated 25 Aug 2026
Cluster Setup5 guides
Network policy, CIS benchmarks, ingress TLS, node metadata protection. 15%.
-
Hands-on Lab 20 min
NetworkPolicy for Cluster-Level Access Control
Four states, each one measured: open, denied, DNS back, and exactly one thing allowed.
Domain 1 - Cluster Setup (15%)Updated 25 Aug 2026
-
Hands-on Lab 19 min
CIS Benchmark Review with kube-bench
One finding fixed and measured - and one that will not clear no matter what you chmod.
Domain 1 - Cluster Setup (15%)Updated 25 Aug 2026
-
Hands-on Lab 20 min
Ingress TLS Configuration
Install a controller, mint a certificate, and read the certificate the server actually served.
Domain 1 - Cluster Setup (15%)Updated 25 Aug 2026
-
Hands-on Lab 18 min
Protecting Node Metadata and Endpoints
The kubelet answers 401 from inside a Pod - and nothing at all after one egress rule.
Domain 1 - Cluster Setup (15%)Updated 25 Aug 2026
-
Hands-on Lab 14 min
Verifying Kubernetes Platform Binaries
A digest that matches, one byte that breaks it, and the thing a checksum cannot prove.
Domain 1 - Cluster Setup (15%)Updated 25 Aug 2026
Cluster Hardening5 guides
RBAC minimisation, ServiceAccounts, apiserver exposure, keeping up with releases. 15%.
-
Hands-on Lab 18 min Paid
Minimizing an Over-Broad RBAC Role
A wildcard Role replaced with two narrow ones - and tested in both directions.
Domain 2 - Cluster Hardening (15%)Updated 25 Aug 2026
-
Hands-on Lab 16 min Paid
Auditing RBAC Permissions
Six read-only queries that give you a cluster's RBAC posture, and a baseline to compare next quarter against.
Domain 2 - Cluster Hardening (15%)Updated 25 Aug 2026
-
Hands-on Lab 17 min Paid
ServiceAccount Tokens and automountServiceAccountToken
Turn the default credential off for a whole namespace, then hand one back on purpose.
Domain 2 - Cluster Hardening (15%)Updated 25 Aug 2026
-
Hands-on Lab 18 min Paid
Restricting Kubernetes API Access
200 without a credential, 403 as system:anonymous - and every Pod can reach the control plane until you stop it.
Domain 2 - Cluster Hardening (15%)Updated 25 Aug 2026
-
Hands-on Lab 22 min Paid
Upgrading Kubernetes to Patch Vulnerabilities
A real upgrade, on a real cluster, checked after every phase - and the step that makes people stop too early.
Domain 2 - Cluster Hardening (15%)Updated 25 Aug 2026
System Hardening4 guides
Host OS footprint, IAM roles, kernel attack surface, AppArmor and seccomp. 10%.
-
Hands-on Lab 17 min Paid
Minimizing the Host OS Footprint
Ten open ports, 765 packages and a kernel that will still load modules - measured, then judged.
Domain 3 - System Hardening (10%)Updated 25 Aug 2026
-
Hands-on Lab 15 min Paid
Least-Privilege Identity and Access on the Node
Two shells, one NOPASSWD line, and four checks this node fails three of.
Domain 3 - System Hardening (10%)Updated 25 Aug 2026
-
Hands-on Lab 18 min Paid
Restricting Node External Network Access
An unauthenticated metrics port handing out the kernel version - found, closed, and the kubelet left untouched.
Domain 3 - System Hardening (10%)Updated 25 Aug 2026
-
Hands-on Lab 22 min Paid
AppArmor and seccomp Profiles for Pods
Two identical Pods, one file write, one Permission denied - and a syscall that stops working.
Domain 3 - System Hardening (10%)Updated 25 Aug 2026
Microservice Vulnerabilities7 guides
Security contexts, Pod Security, Secrets, sandboxing and mTLS. 20%.
-
Hands-on Lab 17 min Paid
Pod Security Admission: enforce, audit and warn
Warn, audit, then enforce - and the privileged Pod that carries on running through all three.
Domain 4 - Minimize Microservice Vulnerabilities (20%)Updated 25 Aug 2026
-
Hands-on Lab 18 min Paid
A securityContext That Passes the Restricted Standard
Four refusals turned into four fields, each one proved from inside the container.
Domain 4 - Minimize Microservice Vulnerabilities (20%)Updated 25 Aug 2026
-
Hands-on Lab 22 min Paid
Encrypting Secrets at Rest in etcd
A card number readable in etcd, then ciphertext - and the Secrets that stay readable until you rewrite them.
Domain 4 - Minimize Microservice Vulnerabilities (20%)Updated 25 Aug 2026
-
Hands-on Lab 16 min Paid
Managing Kubernetes Secrets
The same Secret two ways, and only one of them is in /proc.
Domain 4 - Minimize Microservice Vulnerabilities (20%)Updated 25 Aug 2026
-
Hands-on Lab 20 min Paid
Namespace Isolation for Multi-Tenancy
Six objects, tested from both directions - and the boundary they still cannot draw.
Domain 4 - Minimize Microservice Vulnerabilities (20%)Updated 25 Aug 2026
-
Hands-on Lab 16 min Paid
Sandboxed Containers with gVisor and RuntimeClass
A container that reports a different kernel from the machine it is running on.
Domain 4 - Minimize Microservice Vulnerabilities (20%)Updated 25 Aug 2026
-
Hands-on Lab 20 min Paid
Pod-to-Pod Encryption with Cilium WireGuard
A canary string read off the wire with tcpdump - and then 104 packets with none of it.
Domain 4 - Minimize Microservice Vulnerabilities (20%)Updated 25 Aug 2026
Supply Chain Security7 guides
Base image footprint, image signing, allowed registries, static analysis, scanning. 20%.
-
Hands-on Lab 16 min Paid
Minimizing the Base Image Footprint
Ninety components down to one, and 175 findings down to none - without patching anything.
Domain 5 - Supply Chain Security (20%)Updated 25 Aug 2026
-
Hands-on Lab 15 min Paid
Software Bills of Materials (SBOM)
An inventory you can scan a year later without ever fetching the image again.
Domain 5 - Supply Chain Security (20%)Updated 25 Aug 2026
-
Hands-on Lab 15 min Paid
Container Scanning and Vulnerability Staleness
175 findings, none of them fixable - and the flag that turns a scanner into a gate people keep.
Domain 5 - Supply Chain Security (20%)Updated 25 Aug 2026
-
Hands-on Lab 16 min Paid
Restricting Permitted Image Registries
Two CEL rules, two different refusals - and one thing neither of them can see.
Domain 5 - Supply Chain Security (20%)Updated 25 Aug 2026
-
Hands-on Lab 18 min Paid
Signing and Verifying Artifacts with Cosign
Verified OK - then one character changes and it is not.
Domain 5 - Supply Chain Security (20%)Updated 25 Aug 2026
-
Hands-on Lab 15 min Paid
Static Analysis of Kubernetes Manifests
Five findings with identifiers, before a cluster is involved at all.
Domain 5 - Supply Chain Security (20%)Updated 25 Aug 2026
-
Hands-on Lab 14 min Paid
Static Analysis of a Dockerfile
Five findings in six lines - including the missing USER that everything downstream compensates for.
Domain 5 - Supply Chain Security (20%)Updated 25 Aug 2026
Monitoring and Runtime7 guides
Behavioural analytics, immutability at runtime, and the audit log. 20%.
-
Hands-on Lab 18 min Paid
Enabling Kubernetes Audit Logging
The only record that can name a caller, and the policy file that decides what it costs you.
Domain 6 - Monitoring, Logging and Runtime Security (20%)Updated 25 Aug 2026
-
Hands-on Lab 18 min Paid
Querying Kubernetes Audit Logs
Who read the Secret, and who ran the exec - the two questions nothing else in the cluster can answer.
Domain 6 - Monitoring, Logging and Runtime Security (20%)Updated 25 Aug 2026
-
Hands-on Lab 14 min Paid
Container Immutability at Runtime
One field, and the binary that is running can no longer be replaced underneath it.
Domain 6 - Monitoring, Logging and Runtime Security (20%)Updated 25 Aug 2026
-
Hands-on Lab 16 min Paid
Falco Runtime Detection and Resource Limits
The probe loads, the engine opens, and then the node runs out of memory - which is the finding.
Domain 6 - Monitoring, Logging and Runtime Security (20%)Updated 25 Aug 2026
-
Hands-on Lab 17 min Paid
Identifying the Phases of an Attack
Discovery, lateral movement, and the reach for the data - two of the three succeed.
Domain 6 - Monitoring, Logging and Runtime Security (20%)Updated 25 Aug 2026
-
Hands-on Lab 15 min Paid
Threat Detection Across Cluster Layers
One exec, five places to look for it, and three of them say no.
Domain 6 - Monitoring, Logging and Runtime Security (20%)Updated 25 Aug 2026
-
Hands-on Lab 14 min Paid
Assessing Cluster Detection Coverage
The honest inventory at the end of the path: two of four, and neither on purpose.
Domain 6 - Monitoring, Logging and Runtime Security (20%)Updated 25 Aug 2026
Working at Exam Speed2 guides
15-20 tasks in 120 minutes on a live cluster, and what the grader reads.
-
Hands-on Lab 15 min Paid
Common CKS Task Mistakes
Five commands that all said they worked, and none of which did what the task asked.
All six domainsUpdated 25 Aug 2026
-
Hands-on Lab 12 min Paid
Time Management on a Performance Exam
Four measurements on a real cluster, and the one that is longer than the other three together.
All six domainsUpdated 25 Aug 2026
Command Cheat Sheets1 sheet
Searchable references for the tools CKS expects you to drive.
-
Reference 14 min
CKS task cheat sheet
One command per task, with the real answer underneath - and the checks that catch a task you thought you had finished.
kubectl / trivy / cosign / etcdctlUpdated 26 Aug 2026