This cheat sheet is designed for:
Security engineers and DevSecOps teams looking to go beyond default controls
Platform teams managing multi-tenant Kubernetes clusters
Developers responsible for securing workloads in production
What's Included?
Component hardening tips: Lock down etcd, kubelets, and the API server with TLS and RBAC.
Validating admission policy examples: Enforce guardrails like banning privilege escalation and blocking untrusted registries.
Network security guidance: Apply network policies, monitor traffic, and leverage service meshes like Istio or Linkerd.
Pod and workload protections: Use NodeRestriction, prevent privilege escalation, and disable risky volume mounts.
Secrets and credentials management: Store secrets securely with tools like Vault and follow least-privilege access practices.
mTLS for service-to-service traffic: Encrypt and authenticate internal traffic to reduce exposure.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."