Securing Kubernetes Training
This intensive course prepares students for the Certified Kubernetes Security Specialist (CKS) exam. It emphasizes the advanced skills and knowledge required for securing container-based applications and Kubernetes platforms across the entire lifecycle: build, deployment, and runtime. As a security expert in the DevOps world, you will learn to observe rapidly progressing processes, implement Zero Trust principles, and pinpoint security concerns within any container, process, or subsystem without hindering velocity
Securing Kubernetes (CKS)
Course Overview
Harden Cluster and Components: Configure and implement cluster-level hardening techniques for Kubernetes master and worker nodes, ensuring components like the API server and etcd are secure.
Secure System and Microservices: Apply system hardening best practices and deploy security policies to minimize microservices vulnerabilities during runtime and deployment.
Manage Supply Chain Risk: Implement comprehensive supply chain security measures, including image signing and vulnerability scanning, to ensure container images are trusted and compliant.
Monitor, Log, and Secure Runtime: Configure and manage solutions for monitoring, logging, and runtime security, enabling effective threat detection and incident response within the cluster.
Leverage AI for Configuration: Utilize AI Large Language Model (LLM) prompt engineering to efficiently generate, validate, and troubleshoot Kubernetes configuration snippets, accelerating deployment and solution design.
Course Outline
- Module 1: Learning Your Environment & Cluster Setup Underlying Infrastructure Tools (Vim, Tmux)
- Cloud Security Principles & Threat Analysis
- Apply CIS Benchmarks
- Install & Manage Kubernetes with Kubeadm
- Join Node to Cluster / Manage Kubeadm Tokens
- Kubeadm Cluster Upgrade
- Purge/Cleanup Kubernetes Environment
- Module 2: Securing the Control Plane Kubernetes Architecture & Security Concepts
- Securing the kube-apiserver
- Configure and Enable Audit Logging
- Deploy Falco to Monitor System Calls
- Enable Pod Security Policies (PSPs)
- Encrypt Data at Rest (Encryption Configuration)
- Benchmark Cluster with Kube-Bench
- Securing ETCD (Isolation, Snapshot, and Restore)
- Module 3: Container and Application Security Container Essentials and Secure Containers
- Creating and Scanning Images (Trivy, Snyk Security)
- Scan a Running Container (Tracee)
- Implement Security Contexts for Pods
- Deploy AppArmor Profiles
- Isolate Container Kernels (gVisor)
- Implement Pod Security Policies (PSPs)
- Enable Pod Security Standards (PSS)
- Deploy Open Policy Agent (OPA) / Gatekeeper
- Policy as Code Implementation
- Module 4: Access Control and Networking User Administration (Contexts)
- Authentication and Authorization
- Configure Role Based Access Control (RBAC)
- Manage Service Accounts
- Secure and Consume Secrets
- Deploy Secrets with Hashicorp Vault
- Configure NetworkPolicy
- Implement mTLS with Linkerd or istio
- Module 5: Threat Detection and Resilience Threat Detection and Active Analysis
- Host Intrusion Detection (OSSEC)
- Network Intrusion Detection (Suricata)
- Disaster Recovery and Response Plan Deployment
- Kasten K10 Backups
- Manually Install & Validate Kubernetes
- Validation with Sonobuoy
- Kubectl Commands (get, describe, sorting)
- Labels, Selectors, and Annotations
Intended Audience
Individuals holding a CKA certification and interested in or responsible for Cloud Security, DevSecOps, Security Architecture, and Security Engineering in containerized environments.
Prerequisites
- General Kubernetes cluster administration proficiency (equivalent to CKA), and
- deep working knowledge of Linux
Related training topics
Justify your training
Use this sample request letter — copy it into an email to your manager and personalize the bracketed details to make the case for the time and budget.
Sample training request letter
Subject: Request for Cloud Computing training from Applied Technology Academy
[Decision Maker Name],
I'm writing to request time and budget approval to complete Applied Technology Academy's course, Securing Kubernetes Training. The information below outlines how this training benefits our organization, the tasks I'll be able to perform after completing it, and relevant cost and funding details.
Course Description
This intensive course prepares students for the Certified Kubernetes Security Specialist
(CKS) exam. It emphasizes the advanced skills and knowledge required for securing
container-based applications and Kubernetes platforms across the entire lifecycle: build,
deployment, and runtime. As a security expert in the DevOps world, you will learn to
observe rapidly progressing processes, implement Zero Trust principles, and pinpoint
security concerns within any container, process, or subsystem without hindering
velocity Applied Technology Academy is an award-winning, SBA-certified woman-owned training provider (est. 2008) whose instructors are active practitioners; the course is hands-on with virtual labs and a learn-by-doing methodology.
Course Objectives
Once I've completed the course, I'll have hands-on, job-ready skills in cloud computing that I can apply immediately to our work.
Expected Organizational Benefits
After completing this course, I will be better equipped to apply these skills directly to our projects, reduce our reliance on outside expertise, strengthen our team's capabilities, and share what I learn with colleagues.
Expected Cost & Funding
Course fee: [request an itemized quote at the link below]. Applied Technology Academy supports multiple funding paths that may reduce or cover this cost: GSA MAS purchasing and government purchase orders, military credentialing funding (Army CA, AF COOL, CG COOL), VA GI Bill and VR&E, ATA Flexible Spending, and student financing. Private team cohorts are available if colleagues should attend with me.
Conclusion
This training provides practical, hands-on experience I can apply immediately to strengthen our work in cloud computing. Additional course information is available at https://appliedtechnologyacademy.com/alta3-research-training/securing-kubernetes-cks-training/.
Thank you for your consideration,
[Your Name]
Design training around your team, not the other way around.
Talk to a training advisor about private cohorts, funding paths and program management.