Every competency the Linux Foundation publishes for the CKS, against what this roadmap actually covers — including the 6 that nothing covers yet. The gaps are the useful part: they are the writing backlog.
Use Network security policies to restrict cluster level access
Use CIS benchmark to review the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi)
Properly set up Ingress with TLS
Protect node metadata and endpoints
Verify platform binaries before deploying
Use Role Based Access Controls to minimize exposure
Exercise caution in using service accounts e.g. disable defaults, minimize permissions on newly created ones
Restrict access to Kubernetes API
Upgrade Kubernetes to avoid vulnerabilities
Minimize host OS footprint (reduce attack surface)
Using least-privilege identity and access management
Minimize external access to the network
Appropriately use kernel hardening tools such as AppArmor, seccomp
Use appropriate pod security standards
Manage Kubernetes secrets
Understand and implement isolation techniques (multi-tenancy, sandboxed containers, etc.)
Implement Pod-to-Pod encryption (Cilium, Istio)
Minimize base image footprint
Understand your supply chain (e.g. SBOM, CI/CD, artifact repositories)
Secure your supply chain (permitted registries, sign and validate artifacts, etc.)
Perform static analysis of user workloads and container images (e.g. Kubesec, KubeLinter)
Perform behavioral analytics to detect malicious activities
Detect threats within physical infrastructure, apps, networks, data, users and workloads
Investigate and identify phases of attack and bad actors within the environment
Ensure immutability of containers at runtime
Use Kubernetes audit logs to monitor access
The 6 outright gaps, ordered by how much of the exam their domain is worth. Each one is also the most useful pull request available right now.
| Domain weight | Domain | Nothing covers this yet |
|---|---|---|
| 20% | Supply Chain Security | Perform static analysis of user workloads and container images (e.g. Kubesec, KubeLinter) |
| 20% | Monitoring, Logging and Runtime Security | Ensure immutability of containers at runtime |
| 15% | Cluster Setup | Use CIS benchmark to review the security configuration of Kubernetes components (etcd, kubelet, kubedns, kubeapi) |
| 15% | Cluster Setup | Protect node metadata and endpoints |
| 15% | Cluster Hardening | Upgrade Kubernetes to avoid vulnerabilities |
| 10% | System Hardening | Minimize host OS footprint (reduce attack surface) |