Hands-on Lab·Kubernetes and Cloud Native Security Associate
Namespaces as a Security Boundary
Namespaces are the most over-trusted object in Kubernetes. This guide shows the same boundary holding on one axis and doing nothing at all on another, with two commands.
Security Fundamentals Guide 23 of 42 Beginner
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 12 min
- Reviewed25 August 2026
Written against the versions above. Cilium 1.18.1 is the CNI - or rather, is not enforcing anything, since no policy exists. The behaviour shown is the Kubernetes default and is the same under any conformant CNI.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 8 - the control that does bound the network.
-
Two namespaces, two Pods, one ping
-
The same boundary, on the API