Cloud & DevOps

Certified Kubernetes Security Specialist (CKS) Training

This training prepares participants for the Certified Kubernetes Security Specialist (CKS) exam.

Duration
6h
Who it's for

Ideal for teams that…

1 The CKS training is intended for IT specialists, security administrators, and engineers who want to gain advanced knowledge of security in Kubernetes environments.
Outcomes after the program

Cloud, automation and CI/CD in practice — hands-on for engineering teams.

During the CKS training, participants will gain knowledge and skills related to ensuring security in Kubernetes clusters, including access control configuration, monitoring, certificate management, auditing and risk assessment, as well as troubleshooting security-related issues in containerized environments.

Program · 6 modules

What we actually do

M01
Cluster Configuration
  • · Applying network security policies to restrict cluster-level access
  • · Using CIS benchmarks to review Kubernetes component security (etcd, kubelet, kube-dns, kube-apiserver)
  • · Proper configuration of Ingress objects with security controls
  • · Protecting node metadata and endpoints
  • · Minimizing GUI use and access
  • · Verifying Kubernetes binaries before deployment
M02
Cluster Hardening
  • · Restricting access to the Kubernetes API
  • · Using Role-Based Access Control (RBAC) to minimize exposure
  • · Avoiding excessive use of ServiceAccounts (disabling defaults, minimizing permissions for new accounts)
  • · Regular Kubernetes upgrades
M03
System Hardening
  • · Minimizing the host OS footprint (reducing attack surface)
  • · Reducing IAM roles
  • · Minimizing external network exposure
  • · Using kernel hardening tools such as AppArmor and seccomp
M04
Minimizing Microservice Vulnerabilities
  • · Setting appropriate OS-level security domains
  • · Managing Kubernetes Secrets
  • · Using container runtime sandboxes in multi-tenant environments (e.g., gVisor, Kata Containers)
  • · Enabling pod-to-pod encryption with mTLS
M05
Supply Chain Security
  • · Minimizing base image size
  • · Securing the supply chain: approved registries, image signing and validation
  • · Performing static analysis of user resources (e.g., Kubernetes manifests, Dockerfiles)
  • · Scanning images for known vulnerabilities
M06
Monitoring, Logging, and Runtime Security
  • · Analyzing syscalls, processes, and file activity at the host and container level to detect malicious behavior
  • · Detecting threats across physical infrastructure, applications, networks, data, users, and workloads
  • · Identifying all phases of an attack, regardless of origin or spread
  • · Performing deep forensic investigations and identifying attackers in the environment
  • · Ensuring container immutability in real time
  • · Using audit logs to monitor access
Every module is adapted to your stack and context. The above is a starting point — not a fixed agenda.
How we work

From brief to retro in 30 days.

01

Brief & diagnosis

A call with the team lead + a short survey for participants. We define goals, gap and context.

02

Program customization

We adapt modules, case studies and code examples to your stack. Approval in 5 days.

03

Workshop

Trainer-led sessions, hands-on, code review. Mentor available between sessions too.

04

Retro + report

Outcome report for the team and lead. 30 days of consulting included.

Inquiry

Send a brief. We'll reply within 1 day.

After a short brief we'll prepare a program and a quote. No obligations — it's just a starting point.

Quote within 48h of the brief
First session within 30 days
Pilot before the full decision
VAT invoice, payment in instalments possible

Ochrona antyspamowa (Cloudflare Turnstile) zostanie aktywowana po wpięciu klucza.