Skip to content

Scope, fee and working days are published on every engagement

CorePhysix Labs Technology lab

Specification CLD·104

CLD · Cloud & DevOps Defined scope Fixed fee

Kubernetes Cluster Hardening Sprint

Network policy, RBAC, resource limits, secrets handling and image scanning applied to a live cluster, closing its default security gaps.

Fee · GST incl.
₹34,999
Duration
15 working days
Deliverables
7

01 Overview

A working cluster and a secure cluster are different things. Left at its defaults, pods reach one another without restriction, containers run as root, nothing caps resource use and secrets are merely base64-encoded in etcd. We close these gaps on a live EKS, AKS or GKE cluster while your workloads keep running. Each change lands as a manifest in your repository, so the hardened state can be reviewed and rebuilt rather than living in someone's shell history.

02 Deliverables

7 items

What you receive at handover

  1. D01 Network policies that deny by default and allow only named traffic per namespace
  2. D02 RBAC review, with service accounts limited to what each workload requires
  3. D03 Pod security standards applied, so containers run as non-root with read-only filesystems
  4. D04 CPU and memory requests and limits based on observed usage
  5. D05 Secrets relocated into AWS Secrets Manager or managed through External Secrets Operator
  6. D06 Container image scanning added to the pipeline, with a rule for handling critical results
  7. D07 Findings report covering residual risks and items deliberately left unchanged

03 Outcomes

What should be true once it ships

  • A compromised container can no longer move freely around the cluster
  • Busy workloads stop taking CPU and memory from their neighbours
  • Documented evidence to share during a customer security review

04 Process

How the 4 stages run

  1. Benchmark Kube-bench runs alongside a manual review against the CIS benchmarks
  2. Rank Findings are ordered by exploitability and blast radius
  3. Remediate Changes roll out namespace by namespace, staging ahead of production
  4. Confirm Re-scan, workload health check and handover of the manifests

05 Fit & inputs

A good fit for

  • Clusters built in a hurry during a migration and left as they were
  • Teams answering security questionnaires from enterprise customers
  • Platforms where a single compromised pod could reach the database

What we need from you

  • Cluster-admin rights, plus a staging cluster close enough to production to test against
  • A named owner for each workload to answer questions about its traffic
  • A change window for enforcing the network policies

These inputs are collected through the technical brief in your dashboard after payment. The duration is counted from when they arrive.

06 Answers

Questions about this engagement

We map actual traffic before enforcing anything and start in audit mode, so any breakage surfaces in staging first.

Only to verify the result, using an account you create and remove afterwards. Nothing is applied until you have reviewed it.

No, although a self-managed control plane adds scope. Tell us your setup before ordering.

This is technology work delivered digitally — nothing is shipped. Work is delivered into systems you control within the duration stated above, and the delivery and refund policies set out what happens if a date is missed.

REL Related

Often considered alongside.

All Cloud & DevOps

Terraform AWS Landing Zone

Your AWS environment defined in versioned Terraform with separate accounts and scoped IAM, so every infrastructure change is reviewed.

Terraform modules for IAM, VPC networking, subnets, security groups and core services

Fixed fee · GST incl.

₹44,999

Duration

25 working days

Zero-Downtime Deployment Migration

Blue-green or rolling releases with health checks and automatic rollback, so you ship in working hours without taking the product offline.

Blue-green or rolling deployment on ECS, Kubernetes or EC2

Fixed fee · GST incl.

₹29,999

Duration

14 working days

AWS Cost Reduction Audit

A line-by-line review of your AWS bill that returns ranked savings with rupee values and risks, so cost cuts never endanger production.

Line-by-line breakdown of three months of AWS spend

Fixed fee · GST incl.

₹12,999

Duration

6 working days

GST included

₹34,999

Next step

Have a system that needs building, fixing or securing?