YOUR LEARNING PATH
CKS: Kubernetes Security
Harden a real cluster the way the Certified Kubernetes Security Specialist exam expects: least-privilege RBAC, then policy-based admission control.
Your practice sequence
One exercise at a timeHardening Pods with securityContext
Drop a workload's privileges: run as non-root, forbid privilege escalation, make the root filesystem read-only, and drop all Linux capabilities.
IntermediatePlus20 minLockedPod Security Standards
Turn on built-in Pod Security admission: enforce the restricted standard on a namespace, then deploy a workload hardened enough to be admitted under it.
IntermediatePlus20 minLockedServiceAccount Token Hardening
Most pods never call the Kubernetes API, yet by default every pod gets a mounted API token an attacker can steal. Give a workload its own ServiceAccount and turn token auto-mount off.
IntermediatePlus20 minLockedHardening Secret Consumption
Environment variables leak — through /proc, crash dumps, and child processes. Mount a Secret as a read-only file instead, and scope who can read it down to that single object with RBAC.
IntermediatePlus25 minLockedScoping Access with RBAC
Least privilege is a habit: build Roles, RoleBindings and verify with auth can-i.
IntermediatePlus30 minLockedRestricting Traffic with NetworkPolicy
Lock a namespace down with a default-deny, then open one precise path with a from-and-port allow rule.
IntermediatePlus20 minLockedTLS-Terminating Ingress
Serve traffic over HTTPS: package a certificate and key into a kubernetes.io/tls Secret, then wire an Ingress to terminate TLS for a host using it. A CKS cluster-setup essential.
IntermediatePlus25 minLockedValidating Pods with Kyverno
Write a Kyverno validate policy that enforces a required label, then watch it block a non-compliant workload at admission.
IntermediatePlus30 minLockedMutating Pods with Kyverno
Write a Kyverno policy that injects a team label into every Pod.
IntermediatePlus35 minLockedIn-Tree Policy with CEL
Enforce a required label with a ValidatingAdmissionPolicy — Kubernetes' built-in, controller-free policy engine — using a CEL expression and a binding.
IntermediatePlus25 minLockedBlock Unpinned Images
Supply-chain hygiene at admission: write a Kyverno policy that rejects the mutable :latest tag so every workload must pin an explicit image version, then prove it admits a pinned image and blocks :latest.
IntermediatePlus30 minLocked- Challenge
Secure a Workload
Exam-pace drill: give a workload a scoped identity (ServiceAccount + RBAC), lock the container down, and isolate it with a NetworkPolicy — exact specs, costly hints, tight timer.
AdvancedPlus30 minLocked - Challenge
Lock It Down
An exam-pace security drill: enforce the restricted Pod Security Standard and a token-hardened ServiceAccount, deploy a workload hardened enough to be admitted under it, then isolate it with a NetworkPolicy and scope its RBAC. Every field is graded.
AdvancedPlus30 minLocked
Test yourself
Mock ExamTimed, scored under exam conditions. Take these once the tree feels solid.
60 min · Pro
45 min · Pro