Services

Kubernetes & Cloud-Native Security

Cluster and platform assessments from CKS-certified engineers who commit upstream to KubeVirt and Cilium.

What we test

  • Cluster configuration — API server, kubelet and etcd exposure, admission control, and the CIS Kubernetes Benchmark
  • Identity and RBAC — service account tokens, over-privileged roles and paths to cluster-admin
  • Workload isolation — pod security, container escape and node compromise from a compromised pod
  • Network policy — whether Cilium or other CNI policies actually enforce the segmentation you expect
  • Virtualized workloads — KubeVirt VM isolation and the boundary between VMs and the cluster
  • Supply chain — image provenance, registries, CI/CD pipelines and secrets handling

Assumed-breach testing

We start from a realistic foothold, such as a compromised application pod or leaked CI credential, and show how far an attacker can go.