All learning paths

YOUR LEARNING PATH

CKS: Kubernetes Security

Harden a real cluster the way the Certified Kubernetes Security Specialist exam expects: least-privilege RBAC, then policy-based admission control.

0 / 15 complete0%

Your practice sequence

One exercise at a time
  1. Hardening Pods with securityContext

    Drop a workload's privileges: run as non-root, forbid privilege escalation, make the root filesystem read-only, and drop all Linux capabilities.

    IntermediatePlus20 minLocked
  2. Pod Security Standards

    Turn on built-in Pod Security admission: enforce the restricted standard on a namespace, then deploy a workload hardened enough to be admitted under it.

    IntermediatePlus20 minLocked
  3. ServiceAccount Token Hardening

    Most pods never call the Kubernetes API, yet by default every pod gets a mounted API token an attacker can steal. Give a workload its own ServiceAccount and turn token auto-mount off.

    IntermediatePlus20 minLocked
  4. Hardening Secret Consumption

    Environment variables leak — through /proc, crash dumps, and child processes. Mount a Secret as a read-only file instead, and scope who can read it down to that single object with RBAC.

    IntermediatePlus25 minLocked
  5. Scoping Access with RBAC

    Least privilege is a habit: build Roles, RoleBindings and verify with auth can-i.

    IntermediatePlus30 minLocked
  6. Restricting Traffic with NetworkPolicy

    Lock a namespace down with a default-deny, then open one precise path with a from-and-port allow rule.

    IntermediatePlus20 minLocked
  7. TLS-Terminating Ingress

    Serve traffic over HTTPS: package a certificate and key into a kubernetes.io/tls Secret, then wire an Ingress to terminate TLS for a host using it. A CKS cluster-setup essential.

    IntermediatePlus25 minLocked
  8. Validating Pods with Kyverno

    Write a Kyverno validate policy that enforces a required label, then watch it block a non-compliant workload at admission.

    IntermediatePlus30 minLocked
  9. Mutating Pods with Kyverno

    Write a Kyverno policy that injects a team label into every Pod.

    IntermediatePlus35 minLocked
  10. In-Tree Policy with CEL

    Enforce a required label with a ValidatingAdmissionPolicy — Kubernetes' built-in, controller-free policy engine — using a CEL expression and a binding.

    IntermediatePlus25 minLocked
  11. Block Unpinned Images

    Supply-chain hygiene at admission: write a Kyverno policy that rejects the mutable :latest tag so every workload must pin an explicit image version, then prove it admits a pinned image and blocks :latest.

    IntermediatePlus30 minLocked
  12. Challenge

    Secure a Workload

    Exam-pace drill: give a workload a scoped identity (ServiceAccount + RBAC), lock the container down, and isolate it with a NetworkPolicy — exact specs, costly hints, tight timer.

    AdvancedPlus30 minLocked
  13. Challenge

    Lock It Down

    An exam-pace security drill: enforce the restricted Pod Security Standard and a token-hardened ServiceAccount, deploy a workload hardened enough to be admitted under it, then isolate it with a NetworkPolicy and scope its RBAC. Every field is graded.

    AdvancedPlus30 minLocked

Test yourself

Mock Exam

Timed, scored under exam conditions. Take these once the tree feels solid.

CKS Mock Exam — Core

60 min · Pro

Locked
CKS — Beyond ExamBeyond Exam

45 min · Pro

Locked