Hands-on Lab·Certified Kubernetes Security Specialist
Minimizing the Host OS Footprint
A Kubernetes node is a Linux box, and most of what makes it dangerous was installed before Kubernetes was. This guide measures the footprint four ways - what is listening, what is running, what is installed and what the kernel will still do - and gives you the numbers to argue with.
System Hardening Guide 14 of 40 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1
- Built withkubeadm v1.36.3
- TimeAbout 17 min
Measured on a worker node, because a control plane has a larger and more justifiable surface. Every command here is read-only.
- Host kernel7.0.0-29
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA7001 | 192.168.0.51 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA7001-NODE01 | 192.168.0.52 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
This guide includes
Use this when the node itself is in scope. This matters because a Kubernetes node is a Linux box, and most of what makes it dangerous was installed by the distribution rather than by you.
- splitting the node's listeners by whether anything else can actually reach them
- counting services, packages, and the tools inside them that nothing needs
- reading the kernel surface underneath - modules, version, and AppArmor
Before you start
- guide 5 - the scored version of this.
-
What this node is listening on
-
What is running that nothing needs
-
The kernel surface underneath