Lab 03 · Harden declarative infrastructure

Kubernetes and Infrastructure-as-Code Security Lab

Edit manifests, scan configurations, enforce admission policy, simulate kubectl and Terraform commands, and improve a workload until it meets a restrictive security baseline.

YAML editorPolicy as codeCluster simulator

Infrastructure security workbench

Select a scenario, policy profile, and file

Not applied
Posture score
--
weighted configuration checks
Violations
0
current files
Admission
--
selected policy profile
Network exposure
--
service and policy model

deployment.yaml

Edit Kubernetes or Terraform code and rerun the scanners

Policy analysis

Modeled IaC scan and admission findings

Scan the current scenario to generate policy findings.

Simulated cluster topology

Exposure and communication paths change with Service and NetworkPolicy settings

Cluster empty
Solid path: allowedDashed path: blocked or not exposed

Kubernetes and IaC terminal

Simulated kubectl, scanner, policy, and Terraform commands

student@iac-lab
student@iac:~$