Cloud & Cloud Security

Kubernetes Security for Engineers

This course delivers an end‑to‑end view of Kubernetes security, focused on real attack surfaces and production‑grade defenses.

Participants learn how real Kubernetes breaches happen, how to harden workloads and clusters, and how to detect runtime threats using Falco and eBPF. They secure network traffic with NetworkPolicies, WireGuard, and mTLS, manage secrets using Vault and External Secrets, enforce RBAC and admission controls, and implement policy‑as‑code with OPA and Kyverno. Incident response, audit log analysis, and recovery procedures are practiced, while mapping skills directly to the CKS certification.

Show dates

    Kubernetes Security for Engineers

Preise ab € 4.590 zzgl. 19% Ust

Duration: 4 days

Level: Advanced

Code: KUB-SEC-ENG

CPEs: 26

Buchen Sie noch heute online oder rufen Sie uns an unter +49 7031 2024741wenn Sie Hilfe bei der Auswahl des richtigen Kurses benötigen oder über Firmenrabatte sprechen möchten.


Secure Kubernetes clusters and workloads end to end and master real‑world attacks, hardening, and incident response.

  • Expert‑level Kubernetes security training
  • Strong focus on real production attack and defense scenarios
  • Extensive hands‑on labs with industry‑standard tools
  • Ideal preparation for the CKS certification
  • Covers platform, network, and application security
  • Small class sizes for in‑depth learning
  • Trainers are hands‑on Kubernetes and cloud security practitioners
  • Modern training and testing center (PSI / Pearson VUE SELECT/ Kryterion)
  • Catering included, nearby hotel recommendations available
  • Kubernetes for Engineers course or equivalent hands‑on experience
  • Confidence deploying and managing workloads on Kubernetes

This course is intended for:

  • Platform engineers
  • Senior software developers
  • DevOps and security engineers
  • Site Reliability Engineers
  • Kubernetes administrators
  • Engineers responsible for securing Kubernetes platforms
  • Professionals preparing for the CKS certification

Day 1: Kubernetes Security Foundations and Supply Chain

  • Introduction to Kubernetes security
  • Container vs VM security considerations
  • Kubernetes architecture review
  • Cluster lifecycle, provisioning, scaling, updates
  • Shared responsibility model
  • Kubernetes attack surfaces and threat vectors
  • Real‑world breach examples
  • Security principles, least privilege, zero trust, defense in depth
  • Container supply chain security
  • Image scanning with Trivy
  • Image signing, validation, SBOMs
  • Lab: Scanning container images

Day 2: Runtime, Network, and Data Security

  • Container runtime architecture
  • Runtime hardening, seccomp, AppArmor, SELinux
  • eBPF‑based threat detection
  • Runtime security with Falco
  • Lab: Detecting runtime threats
  • Network security model
  • NetworkPolicies and DNS security
  • WireGuard for node networking encryption
  • Service Mesh and mTLS with Istio
  • Lab: Implementing mTLS
  • Data security
  • etcd encryption and secrets encryption at rest
  • Lab: Encrypting Kubernetes secrets

Day 3: Identity, Policies, and Cluster Security

  • Secrets management limitations
  • External Secrets Operator, SealedSecrets, SOPS
  • Vault integration and secret rotation
  • Lab: External secrets
  • Authentication and authorization
  • RBAC, ServiceAccounts, Admission Controllers
  • Kyverno as admission webhook
  • Cloud identity integrations, IRSA, Workload Identity, Managed Identity
  • Node and host hardening
  • Control plane hardening
  • CIS Kubernetes Benchmark
  • Lab: Running kube‑bench
  • Policy‑as‑Code with OPA and Kyverno
  • Lab: Enforcing Pod Security Standards

Day 4: Multi‑Tenancy, Backup, and Incident Response

  • Multi‑tenancy models and isolation strategies
  • Namespace isolation and resource quotas
  • Lab: Implementing quotas and limits
  • Network and workload segmentation
  • Backup and disaster recovery
  • etcd backups and encryption
  • Velero backup and restore
  • Lab: Backup and restore etcd
  • Monitoring and incident response
  • Audit logs and security events
  • Lab: Customizing audit logs
  • Detection, forensics, and response playbooks
  • CKS exam outlook and preparation strategy
You receive a Schönbrunn TASC certificate of participation and a Credly badge with CPE points to showcase your Kubernetes skills and support your professional growth.

Find your date for
Kubernetes Security for Engineers

Book your slot - € 4.590 plus 19% VAT

No suitable date?

Whether the listed dates don’t fit your schedule or none are currently available, just let us know your requirements! We’ll be happy to arrange a custom date or an in-house training tailored specifically for your team.

Custom Request