[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-0-en-105":3,"doc-seo-203723-105":59,"doc-detail-203723-en":130},{"code":4,"msg":5,"data":6},0,"success",[7,13,18,23,28,33,38,43,48,51,55],{"id":8,"doc_module":4,"doc_module_name":9,"category_name":10,"show_sort_weight":11,"slug":12},1,"Document","Story & Novel",90,"story-novel",{"id":14,"doc_module":4,"doc_module_name":9,"category_name":15,"show_sort_weight":16,"slug":17},2,"Literature",80,"literature",{"id":19,"doc_module":4,"doc_module_name":9,"category_name":20,"show_sort_weight":21,"slug":22},4,"Exam",70,"exam",{"id":24,"doc_module":4,"doc_module_name":9,"category_name":25,"show_sort_weight":26,"slug":27},5,"Comic",60,"comic",{"id":29,"doc_module":4,"doc_module_name":9,"category_name":30,"show_sort_weight":31,"slug":32},6,"Technology",50,"technology",{"id":34,"doc_module":4,"doc_module_name":9,"category_name":35,"show_sort_weight":36,"slug":37},7,"Healthcare",40,"healthcare",{"id":39,"doc_module":4,"doc_module_name":9,"category_name":40,"show_sort_weight":41,"slug":42},8,"Research & Report",30,"research-report",{"id":44,"doc_module":4,"doc_module_name":9,"category_name":45,"show_sort_weight":46,"slug":47},9,"Religion & Spirituality",20,"religion-spirituality",{"id":46,"doc_module":4,"doc_module_name":9,"category_name":49,"show_sort_weight":46,"slug":50},"World Cup","world-cup",{"id":52,"doc_module":4,"doc_module_name":9,"category_name":53,"show_sort_weight":52,"slug":54},10,"Lifestyle","lifestyle",{"id":56,"doc_module":4,"doc_module_name":9,"category_name":57,"show_sort_weight":24,"slug":58},19,"General","general",{"code":4,"msg":60,"data":61},"ok",{"site_id":62,"language":63,"slug":64,"title":65,"keywords":66,"description":67,"schema_data":68,"social_meta":123,"head_meta":125,"extra_data":127,"updated_unix":129},105,"en","certified-kubernetes-security-specialist-cks-study-guide-chapter-2-cluster-setup","Certified Kubernetes Security Specialist (CKS) Study Guide - Chapter 2 - Cluster Setup","","Chapter 2 focuses on Kubernetes cluster setup from a security perspective, narrowing coverage to security-specific responsibilities rather than general administration. The chapter guides readers through using network policies to control Pod-to-Pod connectivity, running kube-bench/CIS-style tooling to identify risks in cluster components, and hardening access paths such as Ingress with TLS termination. It also covers protecting node metadata and endpoints, securing Dashboard-related functions, validating binaries against hashes, and applying Kubernetes component security best practices with practical scenarios and verification steps.",{"@graph":69,"@context":122},[70,84,105],{"@type":71,"itemListElement":72},"BreadcrumbList",[73,77,79,82],{"item":74,"name":75,"@type":76,"position":8},"https://docshare.wps.com","Home","ListItem",{"item":78,"name":9,"@type":76,"position":14},"https://docshare.wps.com/document/",{"item":80,"name":20,"@type":76,"position":81},"https://docshare.wps.com/document/exam/",3,{"item":83,"name":65,"@type":76,"position":19},"https://docshare.wps.com/document/certified-kubernetes-security-specialist-cks-study-guide-chapter-2-cluster-setup/203723/",{"url":83,"name":65,"@type":85,"image":86,"author":91,"headline":65,"publisher":94,"fileFormat":97,"inLanguage":63,"description":67,"dateModified":98,"datePublished":99,"encodingFormat":97,"isAccessibleForFree":100,"interactionStatistic":101},"DigitalDocument",{"url":87,"@type":88,"width":89,"height":90},"https://docshare.wps.com/thumbnails/certified-kubernetes-security-specialist-cks-study-guide-chapter-2-cluster-setup/203723.png","ImageObject",300,407,{"name":92,"@type":93},"Fahsai","Person",{"url":74,"name":95,"@type":96},"DocShare","Organization","application/pdf","2026-10-09","2026-09-04",true,{"@type":102,"interactionType":103,"userInteractionCount":52},"InteractionCounter",{"@type":104},"ViewAction",{"@type":106,"mainEntity":107},"FAQPage",[108,114,118],{"name":109,"@type":110,"acceptedAnswer":111},"What security topics does Chapter 2 of the CKS Study Guide cover?","Question",{"text":112,"@type":113},"Chapter 2 covers security-focused cluster setup, including network policies for Pod-to-Pod traffic, using benchmark tooling to find risks, configuring an Ingress with TLS, protecting node metadata and endpoints, securing GUI access, and verifying platform binaries against checksums.","Answer",{"name":115,"@type":110,"acceptedAnswer":116},"How do network policies help in Kubernetes cluster security?",{"text":117,"@type":113},"Network policies work like firewall rules for Pod-to-Pod communication, letting rules specify traffic direction (ingress/egress), scope within or across namespaces, and targeted ports to restrict lateral movement.",{"name":119,"@type":110,"acceptedAnswer":120},"Why verify Kubernetes platform binaries against hashes?",{"text":121,"@type":113},"Verifying binaries against their expected hashes helps detect tampering or malicious code injection, ensuring the running platform components match trusted integrity checksums.","https://schema.org",{"og:url":83,"og:type":124,"og:title":65,"og:site_name":95,"og:description":67},"article",{"robots":126,"canonical":83},"index,follow",{"doc_id":128,"site_id":62},203723,1790019250,{"code":4,"msg":5,"data":131},{"doc_id":128,"user_id":132,"nickname":92,"user_avatar":133,"doc_module":4,"category_id":19,"category_name":20,"doc_title":65,"doc_description":67,"doc_content":134,"file_id":135,"file_url":136,"file_type":137,"file_size":138,"view_count":52,"is_deleted":4,"is_public":8,"is_downloadable":8,"audit_status":8,"page_count":139,"language":140,"language_code":63,"site_id":62,"html_lang":63,"table_of_contents":141,"faqs":142,"seo_title":143,"seo_description":67,"update_tm":144,"read_time":145},549768702563,"https://ap-avatar.wpscdn.com/avatar/8000c4aa63b76e948b?x-image-process=image/resize,m_fixed,w_180,h_180&k=1786536092046926083","Certified Kubernetes Security Specialist (CKS) Study Guide  \nIn-Depth Guidance and Practice  \nFree Chapter  \nBenjamin Muschko  \nCertified Kubernetes Security Specialist (CKS) Study Guide In-Depth Guidance and Practice  \nThis excerpt contains Chapter 2. The complete book is available on the O’Reilly Online Learning Platform and through other retailers.  \nBenjamin Muschko  \nBeijing  Boston  Farnham  Sebastopol  Tokyo   \nCertified Kubernetes Security Specialist (CKS) Study Guide  \nby Benjamin Muschko  \nCopyright © 2023 Automated Ascent, LLC. All rights reserved.  \nPrinted in the United States of America.  \nPublished by O’Reilly Media, Inc., 1005 Gravenstein Highway North, Sebastopol, CA 95472.  \nO’Reilly books may be purchased for educational, business, or sales promotional use. Online editions are also available for most titles ([https://oreilly.com](https://oreilly.com)). For more information, contact our corporate/institu‐  \ntional sales department: 800-998-9938 or [corporate@oreilly.com](corporate@oreilly.com).  \nAcquisitions Editor: John Devins  \nDevelopment Editor: Michele Cronin  \nProduction Editor: Beth Kelly  \nCopyeditor: Liz Wheeler  \nProofreader: Amnet Systems, LLC  \nIndexer: Potomac Indexing, LLC  \nInterior Designer: David Futato  \nCover Designer: Karen Montgomery  \nIllustrator: Kate Dullea  \nJune 2023: First Edition  \nRevision History for the First Edition  \n2023-06-08: First Release  \nSee [https://oreilly.com/catalog/errata.csp?isbn=9781098132972](https://oreilly.com/catalog/errata.csp?isbn=9781098132972 for)[ for](https://oreilly.com/catalog/errata.csp?isbn=9781098132972 for) release details.  \nThe O’Reilly logo is a registered trademark of O’Reilly Media, Inc. Certified Kubernetes Security Specialist (CKS) Study Guide, the cover image, and related trade dress are trademarks of O’Reilly Media, Inc.  \nThe views expressed in this work are those of the author, and do not represent the publisher’s views. While the publisher and the author have used good faith efforts to ensure that the information and instructions contained in this work are accurate, the publisher and the author disclaim all responsibility for errors or omissions, including without limitation responsibility for damages resulting from the use of or reliance on this work. Use of the information and instructions contained in this work is at your own risk. If any code samples or other technology this work contains or describes is subject to opensource licenses or the intellectual property rights of others, it is your responsibility to ensure that your use thereof complies with such licenses and/or rights.  \n978-1-098-13297-2  \n[LSI]  \nTable of Contents  \n2. Cluster Setup............................................................... 1  \nUsing Network Policies to Restrict Pod-to-Pod Communication 1  \nScenario: Attacker Gains Access to a Pod 2  \nObserving the Default Behavior 3  \nDenying Directional Network Traffic 5  \nAllowing Fine-Grained Incoming Traffic 6  \nApplying Kubernetes Component Security Best Practices 8  \nUsing kube-bench 8  \nThe kube-bench Verification Result 9  \nFixing Detected Security Issues 10  \nCreating an Ingress with TLS Termination 12  \nSetting Up the Ingress Backend 13  \nCreating the TLS Certificate and Key 15  \nCreating the TLS-Typed Secret 15  \nCreating the Ingress 16  \nCalling the Ingress 18  \nProtecting Node Metadata and Endpoints 18  \nScenario: A Compromised Pod Can Access the Metadata Server 19  \nProtecting Metadata Server Access with Network Policies 20  \nProtecting GUI Elements 21  \nScenario: An Attacker Gains Access to the Dashboard Functionality 21  \nInstalling the Kubernetes Dashboard 22  \nAccessing the Kubernetes Dashboard 22  \nCreating a User with Administration Privileges 23  \nCreating a User with Restricted Privileges 25  \nAvoiding Insecure Configuration Arguments 27  \nVerifying Kubernetes Platform Binaries 27  \nScenario: An Attacker Injected Malicious Code into Binary 27  \nVerifying a Binary Against Hash 28  \nSummary 29","cbCaibwMwRbkeeoy","https://ap.wps.com/l/cbCaibwMwRbkeeoy","pdf",3351571,39,"English","# Cluster Setup\n## Using Network Policies to Restrict Pod-to-Pod Communication\n## Applying Kubernetes Component Security Best Practices\n## Creating an Ingress with TLS Termination\n## Protecting Node Metadata and Endpoints\n## Protecting GUI Elements\n## Verifying Kubernetes Platform Binaries\n## Summary\n## Exam Essentials\n## Sample Exercises","[{\"question\":\"What security topics does Chapter 2 of the CKS Study Guide cover?\",\"answer\":\"Chapter 2 covers security-focused cluster setup, including network policies for Pod-to-Pod traffic, using benchmark tooling to find risks, configuring an Ingress with TLS, protecting node metadata and endpoints, securing GUI access, and verifying platform binaries against checksums.\"},{\"question\":\"How do network policies help in Kubernetes cluster security?\",\"answer\":\"Network policies work like firewall rules for Pod-to-Pod communication, letting rules specify traffic direction (ingress/egress), scope within or across namespaces, and targeted ports to restrict lateral movement.\"},{\"question\":\"Why verify Kubernetes platform binaries against hashes?\",\"answer\":\"Verifying binaries against their expected hashes helps detect tampering or malicious code injection, ensuring the running platform components match trusted integrity checksums.\"}]","Certified Kubernetes Security Specialist (CKS) Study Guide - Chapter 2 - Cluster Setup | PDF",1788562877,98]