Assess · Fixed scope
Kubernetes Security Audit
An acks.io Kubernetes security audit is a fixed-scope, fixed-fee review of your clusters' security: control plane and node configuration, RBAC and identity, workload security, network policies, secrets and the container supply chain. You get a written report with every finding rated by severity, the evidence behind it, and a concrete fix.
Built for teams that run Kubernetes in production and want an independent answer to “how exposed are we?” before a customer, an auditor or an attacker asks.
Who it is for
When a Kubernetes security audit makes sense
- A customer security questionnaire, SOC 2 or ISO 27001 audit is coming and you want to find the infrastructure gaps first.
- Your clusters grew faster than your security practices. RBAC, network policies and pod security were “later” items that never came.
- You inherited a cluster after a team change or acquisition and don't know what it trusts.
- You are about to handle more sensitive data (health, financial, legal or personal data) on Kubernetes.
- You want an independent baseline before investing in hardening, so the work is prioritised by real risk.
What we review
Six areas, from the control plane to the container image
Findings combine automated checks with manual review of how your clusters are actually used. We use public references such as the CIS Kubernetes Benchmark, the Kubernetes Pod Security Standards and the NSA/CISA Kubernetes Hardening Guidance, and adapt them to what your provider manages for you.
Cluster and control plane
- API server exposure and authentication
- Kubernetes version and support window
- Node OS, kubelet and container runtime settings
- Encryption of secrets at rest
- Managed-service settings on EKS, GKE or AKS
Identity and RBAC
- cluster-admin and wildcard role bindings
- Service account tokens and automounting
- Workload identity to cloud APIs
- Human access, SSO and offboarding
- CI/CD deployer permissions
Workload security
- Containers running as root or privileged
- Capabilities, privilege escalation, read-only filesystems
- Host namespaces and hostPath mounts
- Pod Security admission and policy enforcement
- Resource limits as a denial-of-service control
Network
- NetworkPolicies and default-deny coverage
- Ingress, load balancers and public exposure
- TLS termination and internal encryption
- Egress control to the internet and cloud metadata
- Service mesh configuration, if present
Secrets and supply chain
- Secrets in manifests, environment variables and Git
- External secret store integration
- Image sources, registries and tag pinning
- Vulnerability scanning in CI and at admission
- Helm charts and third-party operators
Detection and recovery
- API server audit logging and retention
- Security-relevant alerting
- Backup and restore of cluster state and volumes
- Incident runbooks and access for responders
What you receive
A report your engineers can act on
- Findings reportEvery finding with severity, evidence, affected resources, impact and a concrete fix — manifests, policies or Terraform where relevant.
- Prioritised remediation planOrdered by risk and effort, split into quick wins and structural changes, so you know what to do first.
- Executive summaryA short overview for leadership, customers or auditors, without the kubectl output.
- Readout sessionWe walk your engineers through the findings and answer questions about the fixes.
How it works
From scoping call to remediation plan
Scope
We agree which clusters, namespaces and accounts are in scope, and send a written scope and fixed fee.
Access
You grant read-only access to clusters, cloud account and repositories. We never need write access for an audit.
Review
Automated checks plus manual review of RBAC, workloads, network and supply chain, with questions to your team where context matters.
Readout
You receive the report and remediation plan, and we walk through it together. Then you revoke our access.
After the audit
Fix it yourself, or have us do it
The report is written so that your team can implement every fix without us. If you would rather not, there are two follow-ups.
FAQ
Frequently asked questions
What does a Kubernetes security audit include?
An acks.io Kubernetes security audit reviews cluster and control plane configuration, identity and RBAC, workload security settings, network policies and ingress, secrets management, container image supply chain, and logging and detection. Findings are rated by severity and come with concrete remediation steps.
Which Kubernetes distributions do you audit?
Managed Kubernetes on EKS, GKE and AKS, and self-managed clusters including on-premises installations. The review adapts to what your provider manages and what you manage.
What access do you need?
Read-only access to the cluster and the surrounding cloud account, plus read access to the repositories that define your manifests, Helm charts or Terraform. We do not need write access to run the audit.
Does the audit cover compliance frameworks like SOC 2 or ISO 27001?
The audit is a technical security review, not a certification. The findings map well to the infrastructure controls auditors ask about, and the report is often used as evidence of technical due diligence.
Can you fix what you find?
Yes. Remediation is optional and quoted separately as an Infrastructure Hardening project, or your team can implement the fixes from the report.
How much does it cost?
Every audit has a fixed fee agreed before we start. The fee depends on the number of clusters and the scope, and we quote it in writing after a 30-minute scoping call.
Talk to an engineer about your infrastructure
A 30-minute call with a senior engineer, not a sales rep. We ask about your setup and what is worrying you, and tell you honestly whether we can help.