Hands-on Lab·Certified Kubernetes Security Specialist
Least-Privilege Identity and Access on the Node
Identity and access management in this domain means the host's, not the cluster's: who can log in, what they can become, and what a shell on this machine is worth. This guide answers all three and finishes with four checks you can run on any node in ten seconds.
System Hardening Guide 15 of 40 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 15 min
- Reviewed25 August 2026
Written against the versions above. This is a lab node and it does not pass every check. The guide says so rather than quietly using a hardened example.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA7001 | 192.168.0.51 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA7001-NODE01 | 192.168.0.52 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
-
Who can log in at all, and what they become
-
How they get here
-
What a shell on this node is worth
-
The four checks worth running everywhere