---
title: "Kubernetes App Platforms & Platform Security"
description: "A 3-day hands-on workshop on securing STACKIT Kubernetes Engine environments: cluster, network, and workload security, plus incident detection and response."
scfAsset:
  managed: false
  category: "workshop"
  maintainers:
    - user: "can.celik1"
  external: true
  tags: ["STACKIT University", "Learning", "Workshop", "Kubernetes", "Security"]
source_url: "https://framework.stackit.cloud/advisory/assetcontainer/stackit/workshop-kubernetes-app-platforms-security/"
source_file: "docs/advisory/assetcontainer/stackit/workshop-kubernetes-app-platforms-security.mdx"
---

## Overview

In recent years, Kubernetes has established itself as the standard framework for the underlying infrastructure of SaaS products. With STACKIT Kubernetes Engine (SKE), STACKIT provides its customers with a "Kubernetes as a Service" product — but even with a managed service, administrators still need to get numerous security-relevant aspects right to ensure secure operations, including supply chain security, runtime detection, and application isolation.

This workshop examines these security aspects across the entire cluster lifecycle: from initial configuration through operations to handling newly discovered or published vulnerabilities (CVEs). It also covers how deployment pipelines for SaaS products can be designed to prevent typical supply chain attacks.

### Target Audience & Requirements

Kubernetes administrators with good Linux skills. Prerequisites are either CKA certification from the Linux Foundation or equivalent knowledge of the architecture and operation of Kubernetes clusters.

### Format

- Duration: 3 days
- Location: remote or onsite
- Language: English or German
- Participants: up to 10

### Learning Objectives

**Introduction to Cloud Security Concepts**
- The 4 Cs of Cloud-Native Security: Code, Container, Cluster, and Cloud
- Assessment, Prevention, Detection, Reaction
- Attack surfaces and types

**Cluster Security**
- Image supply chains
- Policy-based control
- Runtime sandbox

**Network Security**
- Netfilter management and implementation
- Pod-to-pod encryption
- Restricting cluster-level access

**Workload Security**
- Analyzing workloads
- SELinux fundamentals
- Implementing AppArmor

**Detecting and Handling Security Incidents**
- Introduction to intrusion detection systems
- Best practices during an incident
- Post-incident best practices
- Threat detection and behavioral analysis

<LinkCard title="Request this Workshop" href="https://university.stackit.cloud" />
