All skills
wshobson avatar

/k8s-security-policies

@47a5dbc
by Seth Hobsonwshobson/agents40k stars
4,281

Implement Kubernetes security policies including NetworkPolicy, PodSecurityPolicy, and RBAC for production-grade security. Use when securing Kubernetes clusters, implementing network isolation, or enforcing pod security standards.

Use this Skill: https://skilld.dev/gh/wshobson/agents/k8s-security-policies

This session only. Nothing lands on disk.

referencesrbac-patterns.md

≈1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

RBAC Patterns and Best Practices

Common RBAC Patterns

Pattern 1: Read-Only Access

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: read-only
rules:
  - apiGroups: ["", "apps", "batch"]
    resources: ["*"]
    verbs: ["get", "list", "watch"]

Pattern 2: Namespace Admin

apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: namespace-admin
  namespace: production
rules:
  - apiGroups: ["", "apps", "batch", "extensions"]
    resources: ["*"]
    verbs: ["*"]

Pattern 3: Deployment Manager

apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: deployment-manager
  namespace: production
rules:
  - apiGroups: ["apps"]
    resources: ["deployments"]
    verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]
  - apiGroups: [""]
    resources: ["pods"]
    verbs: ["get", "list", "watch"]

Pattern 4: Secret Reader (ServiceAccount)

apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: secret-reader
  namespace: production
rules:
  - apiGroups: [""]
    resources: ["secrets"]
    verbs: ["get"]
    resourceNames: ["app-secrets"] # Specific secret only
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
  name: app-secret-reader
  namespace: production
subjects:
  - kind: ServiceAccount
    name: my-app
    namespace: production
roleRef:
  kind: Role
  name: secret-reader
  apiGroup: rbac.authorization.k8s.io

Pattern 5: CI/CD Pipeline Access

apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
  name: cicd-deployer
rules:
  - apiGroups: ["apps"]
    resources: ["deployments", "replicasets"]
    verbs: ["get", "list", "create", "update", "patch"]
  - apiGroups: [""]
    resources: ["services", "configmaps"]
    verbs: ["get", "list", "create", "update", "patch"]
  - apiGroups: [""]
    resources: ["pods"]
    verbs: ["get", "list"]

ServiceAccount Best Practices

Create Dedicated ServiceAccounts

apiVersion: v1
kind: ServiceAccount
metadata:
  name: my-app
  namespace: production
---
apiVersion: apps/v1
kind: Deployment
metadata:
  name: my-app
spec:
  template:
    spec:
      serviceAccountName: my-app
      automountServiceAccountToken: false # Disable if not needed

Least-Privilege ServiceAccount

apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: my-app-role
  namespace: production
rules:
  - apiGroups: [""]
    resources: ["configmaps"]
    verbs: ["get"]
    resourceNames: ["my-app-config"]

Security Best Practices

  1. Use Roles over ClusterRoles when possible
  2. Specify resourceNames for fine-grained access
  3. Avoid wildcard permissions (*) in production
  4. Create dedicated ServiceAccounts for each app
  5. Disable token auto-mounting if not needed
  6. Regular RBAC audits to remove unused permissions
  7. Use groups for user management
  8. Implement namespace isolation
  9. Monitor RBAC usage with audit logs
  10. Document role purposes in metadata

Troubleshooting RBAC

Check User Permissions

kubectl auth can-i list pods --as john@example.com
kubectl auth can-i '*' '*' --as system:serviceaccount:default:my-app

View Effective Permissions

kubectl describe clusterrole cluster-admin
kubectl describe rolebinding -n production

Debug Access Issues

kubectl get rolebindings,clusterrolebindings --all-namespaces -o wide | grep my-user

Common RBAC Verbs

  • get - Read a specific resource
  • list - List all resources of a type
  • watch - Watch for resource changes
  • create - Create new resources
  • update - Update existing resources
  • patch - Partially update resources
  • delete - Delete resources
  • deletecollection - Delete multiple resources
  • * - All verbs (avoid in production)

Resource Scope

Cluster-Scoped Resources

  • Nodes
  • PersistentVolumes
  • ClusterRoles
  • ClusterRoleBindings
  • Namespaces

Namespace-Scoped Resources

  • Pods
  • Services
  • Deployments
  • ConfigMaps
  • Secrets
  • Roles
  • RoleBindings

Source: SKILL.md on GitHub

No alerts16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides comprehensive documentation and templates for implementing Kubernetes security policies, including RBAC, Network Policies, and Pod Security Standards. It follows industry best practices and contains no malicious code or insecure configurations.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    3 files scanned · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 47a5dbc. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 7 months ago
  • Security
  • kubernetes
  • networking
  • rbac
  • policies
  • pod-security
  • admission-control
  • istio

README badge

README badge for wshobson/agents/k8s-security-policies

Implements Kubernetes security policies including NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards for production clusters. Covers network segmentation, pod security enforcement, least-privilege access control, and admission control with OPA Gatekeeper.

Generated from the current SKILL.md.

Does this skill cover Pod Security Policy or only Pod Security Standards?
It covers Pod Security Standards (the modern approach) with examples for Privileged, Baseline, and Restricted levels. PodSecurityPolicy is mentioned in the description but the guide focuses on the current standard.
What networking plugin do I need for NetworkPolicy to work?
Your cluster's CNI must support NetworkPolicy. The skill includes a troubleshooting command to verify CNI support on your nodes.
Does this include service mesh security with Istio?
Yes. The skill includes Istio PeerAuthentication for mTLS and AuthorizationPolicy examples for enforcing mutual TLS and access control between services.
Can I use OPA Gatekeeper policies with this skill?
Yes. The skill includes ConstraintTemplate and Constraint examples for enforcing custom policies like required labels on deployments.
Does this cover audit logging configuration?
Audit logging is mentioned as a best practice but detailed setup is not included. The skill focuses on Pod Security Standards, NetworkPolicy, RBAC, and admission control.

Generated from the current SKILL.md. These answers refresh after source changes.