Hands-on Lab·Kubernetes and Cloud Native Security Associate
Threat Modeling with STRIDE
A threat modelling framework is a list of questions somebody worked out so you do not have to. STRIDE has six, and each one has an answer on a Kubernetes cluster that a single command will give you. This guide asks all six of this cluster, and every answer is something worth writing down.
Compliance and Frameworks Guide 40 of 42 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 18 min
- Reviewed25 August 2026
Written against the versions above. Every command here is read-only. Nothing is created, changed or deleted, which is what makes this a review you can run on a cluster you do not own.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
-
S for spoofing - who can act without authenticating
-
T for tampering - who can change objects on the way in
-
R for repudiation - what would be left of the evidence
-
I for information disclosure - who can read the secrets
-
D for denial of service - what is unbounded
-
E for elevation of privilege - the grant that is bigger than it looks