Skip to content

Security Considerations

Aleksei Sviridkin edited this page Apr 22, 2025 · 1 revision

Security Considerations

This document outlines the security measures implemented in this Kubernetes cluster and provides guidance on security best practices.

Network Security

Calico Network Policies

Calico provides network policy enforcement:

manifests/tigera-operator/

Network policies define allowed traffic flows between pods, providing microsegmentation within the cluster.

For more information, see the Calico security documentation.

External Access Controls

  1. Traefik Ingress Controller:

    • TLS termination for encrypted traffic
    • Rate limiting against brute force attacks
    • Middleware for authentication
  2. Cloudflare Integration:

    • DDoS protection
    • Web Application Firewall
    • IP-based access controls
  3. Tor Hidden Services:

    • Alternative access method with inherent encryption
    • Anonymization of server location

Authentication and Authorization

RBAC

The cluster uses Kubernetes Role-Based Access Control (RBAC) to control access to resources:

kubectl get clusterroles
kubectl get clusterrolebindings

Custom roles are defined for specific use cases where necessary.

API Server Authentication

K3s configures the API server with secure defaults. For additional authentication:

  1. Service Account Tokens: Used for in-cluster authentication
  2. Client Certificates: Used for admin authentication
  3. External Identity Providers: Can be integrated for user authentication

Secret Management

Sensitive information is stored as Kubernetes Secrets:

kubectl get secrets -A

Consider implementing additional secret management solutions like:

  • HashiCorp Vault
  • Sealed Secrets
  • External secret providers

Certificate Management

cert-manager is deployed for TLS certificate management:

manifests/cert-manager/

It automatically provisions and renews certificates for secure endpoints.

For more information, see the cert-manager documentation.

Container Security

Container Images

Use trusted container images and keep them updated. Consider implementing:

  1. Image scanning in your CI/CD pipeline
  2. Minimal base images (e.g., Alpine, distroless)
  3. Non-root containers where possible

Runtime Security

  1. Pod Security Standards: Define allowed pod configurations
  2. Resource Limits: Prevent resource exhaustion attacks
  3. Seccomp Profiles: Restrict system calls from containers

Node Security

OS Hardening

Basic OS hardening is implemented:

  1. Disabling unused services
  2. Regular updates via system-upgrade-controller
  3. Minimal attack surface

Physical Security

For Raspberry Pi or similar hardware:

  1. Secure physical access to devices
  2. Enable disk encryption where supported
  3. Use secure boot if available

Monitoring and Detection

Implement security monitoring:

  1. Monitor pod creation/deletion events
  2. Watch for suspicious network traffic
  3. Alert on authentication failures
  4. Regular audit of permissions and access

Security Updates

Stay informed about security updates:

  1. Subscribe to Kubernetes security announcements
  2. Update K3s regularly
  3. Keep all applications up to date

Documentation Links

Clone this wiki locally