Repository navigation
Security Considerations
This document outlines the security measures implemented in this Kubernetes cluster and provides guidance on security best practices.
Calico provides network policy enforcement:
manifests/tigera-operator/
Network policies define allowed traffic flows between pods, providing microsegmentation within the cluster.
For more information, see the Calico security documentation.
-
Traefik Ingress Controller:
- TLS termination for encrypted traffic
- Rate limiting against brute force attacks
- Middleware for authentication
-
Cloudflare Integration:
- DDoS protection
- Web Application Firewall
- IP-based access controls
-
Tor Hidden Services:
- Alternative access method with inherent encryption
- Anonymization of server location
The cluster uses Kubernetes Role-Based Access Control (RBAC) to control access to resources:
kubectl get clusterroles
kubectl get clusterrolebindings
Custom roles are defined for specific use cases where necessary.
K3s configures the API server with secure defaults. For additional authentication:
- Service Account Tokens: Used for in-cluster authentication
- Client Certificates: Used for admin authentication
- External Identity Providers: Can be integrated for user authentication
Sensitive information is stored as Kubernetes Secrets:
kubectl get secrets -A
Consider implementing additional secret management solutions like:
- HashiCorp Vault
- Sealed Secrets
- External secret providers
cert-manager is deployed for TLS certificate management:
manifests/cert-manager/
It automatically provisions and renews certificates for secure endpoints.
For more information, see the cert-manager documentation.
Use trusted container images and keep them updated. Consider implementing:
- Image scanning in your CI/CD pipeline
- Minimal base images (e.g., Alpine, distroless)
- Non-root containers where possible
- Pod Security Standards: Define allowed pod configurations
- Resource Limits: Prevent resource exhaustion attacks
- Seccomp Profiles: Restrict system calls from containers
Basic OS hardening is implemented:
- Disabling unused services
- Regular updates via system-upgrade-controller
- Minimal attack surface
For Raspberry Pi or similar hardware:
- Secure physical access to devices
- Enable disk encryption where supported
- Use secure boot if available
Implement security monitoring:
- Monitor pod creation/deletion events
- Watch for suspicious network traffic
- Alert on authentication failures
- Regular audit of permissions and access
Stay informed about security updates:
- Subscribe to Kubernetes security announcements
- Update K3s regularly
- Keep all applications up to date