Kubernetes Security in Poland

Kubernetes Security Assessment

Security testing for Kubernetes, OpenShift, Rancher and on-prem/private cloud environments.

We verify real Kubernetes attack paths: RBAC, service accounts, secrets, ingress, NetworkPolicies, CI/CD, registry, workloads and node hardening.

You receive a technical report for DevOps/CTO, an executive version and a 30/60/90 remediation plan. The report can support security reviews, NIS2/KSC evidence and enterprise customer requirements.

RBAC → secrets → CI/CD
attack path map, not just alert lists
CTO / DevOps / board
technical and executive reporting
NIS2 / KSC / enterprise
technical evidence pack

01

Who it is for

We work with companies running Kubernetes, OpenShift, Rancher, RKE2, K3s or cloud-native environments in production.

software houses
B2B SaaS companies
companies running on-prem/private cloud Kubernetes
DevOps and Platform Engineering teams
companies moving from public cloud to local infrastructure
companies preparing for enterprise customer security reviews
organizations needing technical evidence for NIS2/KSC
teams using CI/CD, GitOps, registry and containers in production

02

What we check

Identity and permissions

  • RBAC
  • Roles / ClusterRoles
  • service accounts
  • tokens
  • access to secrets
  • operator and controller permissions
  • privilege escalation risks

Network and exposure

  • ingress
  • public services
  • NetworkPolicies
  • namespace isolation
  • lateral movement
  • API server exposure
  • kubelet exposure
  • TLS and edge entry points

Workloads and nodes

  • privileged containers
  • hostPath
  • hostNetwork
  • Linux capabilities
  • Pod Security Standards
  • seccomp / AppArmor
  • node hardening
  • vulnerable images and workload configuration

CI/CD and supply chain

  • GitLab CI
  • GitHub Actions
  • Jenkins
  • ArgoCD / Flux
  • registry
  • image scanning
  • SBOM
  • image signing
  • pipeline secrets
  • pipeline → registry → cluster path

Methodology and standards

Assessment grounded in recognized guidance, reported as real risk

We combine manual assessment with references to recognized standards and guides. We do not copy checklists 1:1 — findings are mapped to attack paths, business impact and remediation order.

CIS Kubernetes BenchmarkNSA/CISA Kubernetes Hardening GuidanceOWASP Kubernetes Security Testing GuideOWASP Kubernetes Top 10MITRE ATT&CKKubernetes Security Checklist
  • CIS Kubernetes Benchmark helps structure secure cluster configuration.
  • NSA/CISA guidance reinforces hardening, least privilege, network separation and audit logging.
  • OWASP KSTG and OWASP Kubernetes Top 10 guide technical cluster assessment and common risks.
  • MITRE ATT&CK provides a language for mapping adversary tactics and techniques.

Safe assessment process

Testing without unnecessary production risk

We work within an agreed scope, rules of engagement, test windows and escalation channel. We can start with a read-only configuration review, staging environment or limited production scope. Destructive actions are not performed without separate approval. Findings are documented with evidence, impact and recommended remediation order.

  • scope and ROE agreed before testing
  • test windows and escalation channel
  • read-only review, staging or controlled production scope
  • no destructive actions without separate approval

03

Packages

from PLN 12,000 net

Kube Quick Review

A fast technical review of one Kubernetes, OpenShift, Rancher, RKE2 or K3s cluster. We check key risks: RBAC, service accounts, secret access, ingress, NetworkPolicies, selected workloads and the basic CI/CD connection to the cluster.

Outcome: top 10 risks, short technical report, remediation recommendations and a 60–90 minute CTO/DevOps walkthrough.

from PLN 29,000 net

Kubernetes Security Assessment

A deeper security assessment of a Kubernetes cluster and cloud-native environment. We analyze RBAC, service accounts, secrets, NetworkPolicies, ingress, service exposure, workloads, nodes, registry, logging, monitoring and supply chain basics.

Outcome: technical report, executive version, attack path map, remediation priorities and a 30/60/90 plan.

from PLN 45,000 net

K8s + CI/CD + AppSec Review

An extended assessment for SaaS companies, software houses and platform teams. We connect Kubernetes Security, CI/CD Security, registry, GitOps, API and basic AppSec.

Outcome: full technical evidence pack for CTO, DevOps, board, enterprise customers or security questionnaires.

from PLN 4,900/month net

Monthly Kube Security Delta

A recurring report of cluster security changes: new permissions, exposures, RBAC changes, new workloads, ingress risks, patch status and next-period priorities.

Outcome: monthly security delta report and ongoing control after the assessment.

04

Attack Path Map

We do not show isolated misconfigurations only. We show how issues connect into a real attack path.

This gives CTO and DevOps teams the real route to asset takeover and the order of remediation work.

from finding to scenario

See how individual weaknesses connect into a realistic scenario.

An anonymized scenario based on common mistakes

Example audit finding

Attack path

Vulnerable application → service account token → excessive RBAC → secrets read access → registry access → possible impact on a production deployment.

Impact

A realistic route to partial environment compromise, not just a scanner alert.

Priority

Critical

Remediation

Reduce RBAC permissions, disable token automount where unnecessary, add NetworkPolicy, rotate secrets and introduce admission policy for critical namespaces.

This is a lab example based on issues commonly seen in real Kubernetes environments.

Final deliverable

What the report contains

The value is not the testing activity alone. The report helps teams make decisions, plan fixes and show technical evidence to customers, auditors or management.

  • Executive summary for management
  • Scope and testing limitations
  • Attack path map
  • Critical risks and business impact
  • RBAC, service accounts and privilege escalation
  • Secrets, registry and CI/CD
  • Ingress, NetworkPolicies and east-west traffic
  • Workload/node hardening
  • Logging, monitoring and audit traces
  • 30/60/90 remediation plan
  • Retest checklist

NIS2 / security review / enterprise evidence

NIS2/KSC requires more than policies. It also requires evidence that the technical environment is controlled. CertRank delivers a technical evidence pack for Kubernetes, CI/CD, AppSec and cloud-native environments.

access configuration
environment separation
secret security
monitoring and logging
vulnerabilities and retests
30/60/90 remediation plan

Not just checklists — we publish real CVEs in open-source projects and production software

This is a core CertRank trust asset. Public vulnerabilities in Gitea, Traefik, rclone, SimpleSAMLphp and ProxySQL show hands-on vulnerability research, impact analysis and responsible disclosure.

Gitea

critical CVSS 9.9

Traefik

HTTP/3 mTLS bypass

rclone

critical CVSS 9.8

SimpleSAMLphp

SAML binding bypass

ProxySQL

pre-auth heap overflow CVSS 9.8

See published CVEs

FAQ

Is this a formal NIS2 audit?

No. It is a technical security assessment of Kubernetes, CI/CD and cloud-native environments. The report can support NIS2/KSC technical evidence, security questionnaires or enterprise customer audits.

Do we only receive scanner output?

No. Automation is supporting material. Key findings are manually analyzed, prioritized and described as real attack paths.

Do you test production?

Yes, after agreeing the scope, testing windows and safety rules. Staging testing or configuration review is also possible.

What does management receive?

A short executive report: key risks, business impact, priorities, cost of delay and action plan.

What does DevOps receive?

A technical report: findings, risk, evidence, recommendations, priorities and remediation order.

Can you help after the report?

Yes. We can run a retest, technical workshop or Academy training for the team.

Let us review your Kubernetes

Describe your environment and goal: security review, NIS2/KSC, enterprise customer requirement, prevention, incident or team training.

Enough to start: cluster type, number of environments, cloud/on-prem/hybrid, CI/CD/GitOps, review goal and target date.