Identity and permissions
- RBAC
- Roles / ClusterRoles
- service accounts
- tokens
- access to secrets
- operator and controller permissions
- privilege escalation risks
Kubernetes Security in Poland
Security testing for Kubernetes, OpenShift, Rancher and on-prem/private cloud environments.
We verify real Kubernetes attack paths: RBAC, service accounts, secrets, ingress, NetworkPolicies, CI/CD, registry, workloads and node hardening.
You receive a technical report for DevOps/CTO, an executive version and a 30/60/90 remediation plan. The report can support security reviews, NIS2/KSC evidence and enterprise customer requirements.
01
We work with companies running Kubernetes, OpenShift, Rancher, RKE2, K3s or cloud-native environments in production.
02
Methodology and standards
We combine manual assessment with references to recognized standards and guides. We do not copy checklists 1:1 — findings are mapped to attack paths, business impact and remediation order.
Safe assessment process
We work within an agreed scope, rules of engagement, test windows and escalation channel. We can start with a read-only configuration review, staging environment or limited production scope. Destructive actions are not performed without separate approval. Findings are documented with evidence, impact and recommended remediation order.
03
from PLN 12,000 net
A fast technical review of one Kubernetes, OpenShift, Rancher, RKE2 or K3s cluster. We check key risks: RBAC, service accounts, secret access, ingress, NetworkPolicies, selected workloads and the basic CI/CD connection to the cluster.
Outcome: top 10 risks, short technical report, remediation recommendations and a 60–90 minute CTO/DevOps walkthrough.
from PLN 29,000 net
A deeper security assessment of a Kubernetes cluster and cloud-native environment. We analyze RBAC, service accounts, secrets, NetworkPolicies, ingress, service exposure, workloads, nodes, registry, logging, monitoring and supply chain basics.
Outcome: technical report, executive version, attack path map, remediation priorities and a 30/60/90 plan.
from PLN 45,000 net
An extended assessment for SaaS companies, software houses and platform teams. We connect Kubernetes Security, CI/CD Security, registry, GitOps, API and basic AppSec.
Outcome: full technical evidence pack for CTO, DevOps, board, enterprise customers or security questionnaires.
from PLN 4,900/month net
A recurring report of cluster security changes: new permissions, exposures, RBAC changes, new workloads, ingress risks, patch status and next-period priorities.
Outcome: monthly security delta report and ongoing control after the assessment.
04
We do not show isolated misconfigurations only. We show how issues connect into a real attack path.
This gives CTO and DevOps teams the real route to asset takeover and the order of remediation work.
from finding to scenario
See how individual weaknesses connect into a realistic scenario.
An anonymized scenario based on common mistakes
Attack path
Vulnerable application → service account token → excessive RBAC → secrets read access → registry access → possible impact on a production deployment.
Impact
A realistic route to partial environment compromise, not just a scanner alert.
Priority
Critical
Remediation
Reduce RBAC permissions, disable token automount where unnecessary, add NetworkPolicy, rotate secrets and introduce admission policy for critical namespaces.
This is a lab example based on issues commonly seen in real Kubernetes environments.
Final deliverable
The value is not the testing activity alone. The report helps teams make decisions, plan fixes and show technical evidence to customers, auditors or management.
NIS2/KSC requires more than policies. It also requires evidence that the technical environment is controlled. CertRank delivers a technical evidence pack for Kubernetes, CI/CD, AppSec and cloud-native environments.
This is a core CertRank trust asset. Public vulnerabilities in Gitea, Traefik, rclone, SimpleSAMLphp and ProxySQL show hands-on vulnerability research, impact analysis and responsible disclosure.
critical CVSS 9.9
HTTP/3 mTLS bypass
critical CVSS 9.8
SAML binding bypass
pre-auth heap overflow CVSS 9.8
Training closes the loop after an assessment: the team can practice Kubernetes Security, CKS, CI/CD Security, API, AppSec and AI/LLM Security.
Go to AcademyNo. It is a technical security assessment of Kubernetes, CI/CD and cloud-native environments. The report can support NIS2/KSC technical evidence, security questionnaires or enterprise customer audits.
No. Automation is supporting material. Key findings are manually analyzed, prioritized and described as real attack paths.
Yes, after agreeing the scope, testing windows and safety rules. Staging testing or configuration review is also possible.
A short executive report: key risks, business impact, priorities, cost of delay and action plan.
A technical report: findings, risk, evidence, recommendations, priorities and remediation order.
Yes. We can run a retest, technical workshop or Academy training for the team.