---
title: "Container & Kubernetes Security"
description: "Secure containerized workloads on STACKIT Kubernetes Engine: cluster hardening, workload identity, network controls, and runtime operations."
scfAsset:
  managed: false
  category: "guide"
  maintainers:
    - user: "can.celik1"
  external: true
  tags: ["STACKIT University", "Learning", "Kubernetes Security", "SKE", "Supply Chain", "Runtime"]
source_url: "https://framework.stackit.cloud/architecture/assetcontainer/stackit/container-kubernetes-security/"
source_file: "docs/architecture/assetcontainer/stackit/container-kubernetes-security.mdx"
---

## Course Overview

This five-module course covers the security considerations unique to containerized and Kubernetes workloads on the STACKIT Kubernetes Engine (SKE): container security fundamentals, the Kubernetes security model and what it protects, identity and access control for workloads and secrets, network security and cluster hardening, and secure day-to-day operations through audit logging and runtime monitoring.

A recurring theme runs through the course: Kubernetes access control has to be reasoned about at two distinct levels — who can create or modify cloud resources like clusters and Security Groups at the STACKIT platform level, and who can create, read, or modify Pods, Secrets, and RBAC rules inside the cluster itself. These layers are related but not identical, and conflating them is exactly where excessive-permission incidents come from. Sovereignty at the platform layer only holds if it's matched by equally disciplined access control inside the cluster — this course builds both.

### What You'll Learn
- Harden SKE clusters against CIS Benchmarks and Pod Security Standards
- Apply RBAC and least-privilege access at both the platform and cluster level
- Protect Kubernetes Secrets, ConfigMaps, and service account tokens from misuse
- Secure cluster networking and reduce the overall attack surface
- Implement audit logging and runtime security for ongoing operations

### Modules
- Container Security Fundamentals
- Kubernetes Security Fundamentals
- Identity, Access & Workload Protection
- Network Security & Cluster Hardening
- Secure Operations on Kubernetes

<LinkCard title="View Course on STACKIT University" href="https://university.stackit.cloud/totara/catalog/index.php" />
