Review and harden Kubernetes workloads (pods/Deployments) against Pod Security Standards — privileged containers, host namespaces, hostPath, capabilities, securityContext, and admission enforcement. Use to assess or fix pod-level security for a workload or namespace.
Scanned 9/19/2026
npx -y skills add jassics/awesome-claude-security --skill k8s-workload-hardening --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of K8s Workload Hardening?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/jassics-k8s-workload-hardening)More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.
---
name: k8s-workload-hardening
description: >-
Review and harden Kubernetes workloads (pods/Deployments) against Pod Security
Standards — privileged containers, host namespaces, hostPath, capabilities,
securityContext, and admission enforcement. Use to assess or fix pod-level
security for a workload or namespace.
---
# Goal
Workloads that meet the Pod Security Standards (baseline → restricted), with
dangerous settings removed and enforcement guaranteed by admission, not just policy
on paper.
# What to check / set
1. **Privilege** — no `privileged: true`; `allowPrivilegeEscalation: false`;
`runAsNonRoot: true`, non-zero `runAsUser`.
2. **Host access** — no `hostNetwork`/`hostPID`/`hostIPC`; no `hostPath` mounts; no
host ports.
3. **Capabilities** — `drop: ["ALL"]`, add back only what's required; no `SYS_ADMIN`/
`NET_ADMIN` unless justified.
4. **Filesystem** — `readOnlyRootFilesystem: true`; writable paths via emptyDir/
volumes.
5. **Seccomp / AppArmor** — `seccompProfile: RuntimeDefault` (or stricter); AppArmor
where available.
6. **Resources & images** — set requests/limits (DoS containment); pinned image
digests from trusted registries; non-root images; scanned (`sast-sca`).
7. **Enforcement** — Pod Security Admission level (baseline/restricted) per namespace,
or a policy engine (Kyverno/OPA) so violations are rejected, not just flagged.
# Steps
1. Pull the workload manifests / running pod specs in scope.
2. Compare against the restricted Pod Security Standard; flag each gap with severity.
3. Verify admission actually enforces the standard (test that a bad pod is rejected),
not just that good pods exist.
4. Provide the corrected securityContext/manifest snippets.
# Output
A hardening table: workload · setting · current · required · severity · fix, plus
corrected manifest snippets and the namespace admission level to enforce. Confirmed
issues → `security-reporting:finding`.
# Notes
A privileged or hostPath-mounted container is a node-takeover and often cluster-admin
path — treat those as the top severities. Hardening the pod is only durable if
**admission enforces** the standard; verify enforcement, don't assume it.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!