kubernetes-security
Kubernetes security workflow for cluster hardening, workload isolation, and policy enforcement. Use when RBAC, network policy, pod security, secret handling, or admission controls must be defined before production exposure; do not use for API contract design or requirement prioritization.
Works with
--- name: kubernetes-security description: Kubernetes security workflow for cluster hardening, workload isolation, and policy enforcement. Use when RBAC, network policy, pod security, secret handling, or admission controls must be defined before production exposure; do not use for API contract design or requirement prioritization. license: Apache-2.0 --- # Kubernetes Security ## Overview Use this skill to implement enforceable Kubernetes security controls that reduce blast radius and privilege misuse. ## Scope Boundaries - Use this skill when the task matches the trigger condition described in `description`. - Do not use this skill when the primary task falls outside this skill's domain. ## Shared References - RBAC and NetworkPolicy baselines: - `references/rbac-networkpolicy-baselines.md` ## Templates And Assets - Security control matrix: - `assets/security-control-matrix-template.csv` - Pod security checklist: - `assets/pod-security-checklist.md` ## Inputs To Gather - Workload trust boundaries and risk profile. - Access requirements by service account/namespace. - East-west network communication requirements. - Secret lifecycle and policy constraints. ## Deliverables - Kubernetes security control matrix with ownership. - Pod-level hardening decisions. - RBAC and network isolation policy definitions. - Verification evidence for applied controls. ## Workflow 1. Build control matrix in `assets/security-control-matrix-template.csv`. 2. Define RBAC and network policy using `references/rbac-networkpolicy-baselines.md`. 3. Validate workload hardening with `assets/pod-security-checklist.md`. 4. Verify secret and policy enforcement behavior. 5. Publish accepted risks and remediation backlog. ## Quality Standard - Access controls follow least-privilege principles. - Network paths are explicit and deny-by-default where feasible. - Pod security posture is consistent and reviewable. - Secret handling minimizes exposure in runtime and config. ## Failure Conditions - Stop when critical workloads run without required isolation controls. - Stop when privilege model cannot be audited from manifests/policies. - Escalate when required controls conflict with runtime constraints.
More DevOps & Infrastructure skills
azure-ai
microsoft/azure-skills
Use for Azure AI: Search, Speech, OpenAI, Document Intelligence. Helps with search, vector/hybrid search, speech-to-text, text-to-speech, transcription, OCR. WHEN: AI Search, query search, vector search, hybrid search, semantic search, speech-to-text, text-to-speech, transcribe, OCR, convert text to speech.
appinsights-instrumentation
microsoft/azure-skills
Guidance for instrumenting webapps with Azure Application Insights. Provides telemetry patterns, SDK setup, and configuration references. WHEN: how to instrument app, App Insights SDK, telemetry patterns, what is App Insights, Application Insights guidance, instrumentation examples, APM best practices.
azure-storage
microsoft/azure-skills
Azure Storage Services including Blob Storage, File Shares, Queue Storage, Table Storage, and Data Lake. Answers questions about storage access tiers (hot, cool, cold, archive), when to use each tier, and tier comparison. Provides object storage, SMB file shares, async messaging, NoSQL key-value, and big data analytics. Includes lifecycle management. USE FOR: blob storage, file shares, queue storage, table storage, data lake, upload files, download blobs, storage accounts, access tiers, storage tiers, hot cool cold archive, storage tier comparison, when to use storage tiers, lifecycle management, Azure Storage concepts. DO NOT USE FOR: SQL databases, Cosmos DB (use azure-prepare), messaging with Event Hubs or Service Bus (use azure-messaging).

