Container & Kubernetes Security
Assess modern containerized environments across images, workloads, orchestration, access controls and cluster configuration.
Containers added layers. An application runs in a container, built from an image, scheduled as a pod, governed by a cluster, running on cloud infrastructure. Each layer has its own access model, its own configuration and its own defaults — and the defaults are usually chosen for getting started, not for running in production.
Assessment works through those layers. What an image contains, what a workload is permitted to do, who can reach the cluster's control plane, and whether a compromise in one namespace stays there.
The defaults were chosen for convenience
A cluster that works is not the same as a cluster that is bounded. Permissive RBAC, workloads running with more capability than they need, secrets available more broadly than intended and flat network policy are all states a cluster reaches by working correctly.
The question worth asking is containment: if one workload were compromised, what would that reach next — other namespaces, the node, the control plane, or the cloud credentials the node holds.
The layers this assessment covers.
SEVEN LAYERS, EACH WITH ITS OWN ACCESS MODEL — SCROLL TO SEPARATE
Each layer has its own access model. Findings usually live in the relationship between two of them.
- APPLICATIONApplicationThe code and its configuration
- CONTAINERContainerRuntime capability and what the workload may do
- IMAGEImageWhat ships inside the build, including what was inherited
- PODPod & serviceScheduling, service accounts and exposure
- CLUSTERClusterRBAC, control plane access and network policy
- CLOUDCloud infrastructureNodes, and the cloud identity they carry
Conceptual architecture. Assessment scope is agreed per environment and engagement.
What we assess
This is an assessment service. Findings are documented privately to your team — this page does not provide exploitation commands.
How a container assessment runs
- 01SCOPEAgree clusters, namespaces and environments in scope.
- 02CONFIGReview cluster and control plane configuration.
- 03RBACResolve effective permissions for human and service identities.
- 04WORKLOADAssess workload capability, images and secret handling.
- 05BOUNDARYEstablish what a compromise in one place would reach next.
- 06REPORTFindings, affected resources and remediation guidance.
When Should a Cluster Be Assessed?
Findings your team can act on.
Which of these apply depends on engagement scope.
Weaknesses identified across the environment in scope, with the reasoning behind each.
Settings that widen exposure or weaken a boundary, described precisely enough to locate.
What a finding means in your environment rather than against a generic scoring table.
Supporting detail so findings can be verified rather than taken on trust.
Practical direction on addressing each finding, including where the change belongs.
An order of work, so limited engineering time goes to what matters most.
Verification that addressed findings no longer reproduce, within the agreed retest scope.
Adjacent parts of the infrastructure.
Questions we get asked before an engagement.
Not necessarily. A read-only identity is usually enough to assess configuration and resolve RBAC. Starting from a lower-privileged position is often more informative, because it reflects what a compromised workload would actually see.
Where in scope, yes. Managed services shift some responsibility to the provider but leave RBAC, workload configuration, secrets and network policy with you — which is where most findings sit.
Image review is part of the assessment. Note that image scanning identifies known vulnerable components; it does not tell you what a workload is permitted to do, which is usually the more important question.
The work is primarily read and analysis of configuration, scoped to avoid disruption. Anything with operational risk is agreed in advance rather than decided mid-assessment.
Request a Container Security Assessment
Tell us how many clusters you run, who shares them and what they have access to in your cloud account.
