Kubernetes security
Skill planifest/planifest-framework/planifest-framework/external-skills/kubernetes-security
Kubernetes security workflow for cluster hardening, workload isolation, and policy enforcement. Use when RBAC, network policy, pod security, secret handling, or admission controls must be defined before production exposure; do not use for API contract design or requirement prioritization.From its SKILL.md
npx -y skills add planifest/planifest-framework --skill kubernetes-securityAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
2.1 KB, 361 tokens by cl100k_base, as published. Nobody here has run it
Kubernetes Security
Overview
Use this skill to implement enforceable Kubernetes security controls that reduce blast radius and privilege misuse.
Scope Boundaries
- Use this skill when the task matches the trigger condition described in
description. - Do not use this skill when the primary task falls outside this skill's domain.
Shared References
- RBAC and NetworkPolicy baselines:
references/rbac-networkpolicy-baselines.md
Templates And Assets
- Security control matrix:
assets/security-control-matrix-template.csv
- Pod security checklist:
assets/pod-security-checklist.md
Inputs To Gather
- Workload trust boundaries and risk profile.
- Access requirements by service account/namespace.
- East-west network communication requirements.
- Secret lifecycle and policy constraints.
Deliverables
- Kubernetes security control matrix with ownership.
- Pod-level hardening decisions.
- RBAC and network isolation policy definitions.
- Verification evidence for applied controls.
Workflow
- Build control matrix in
assets/security-control-matrix-template.csv. - Define RBAC and network policy using
references/rbac-networkpolicy-baselines.md. - Validate workload hardening with
assets/pod-security-checklist.md. - Verify secret and policy enforcement behavior.
- Publish accepted risks and remediation backlog.
Quality Standard
- Access controls follow least-privilege principles.
- Network paths are explicit and deny-by-default where feasible.
- Pod security posture is consistent and reviewable.
- Secret handling minimizes exposure in runtime and config.
Failure Conditions
- Stop when critical workloads run without required isolation controls.
- Stop when privilege model cannot be audited from manifests/policies.
- Escalate when required controls conflict with runtime constraints.
What ships with it: 1 file
11.3 KB alongside SKILL.md
- attribution.txt11.3 KB