Skip to content

New: Starter plans from ₹100 — fixed-price checks and reviews, GST included

Container Cluster Hardening Sprint

We close the default gaps in a running container cluster: network policy, access control, resource limits, secrets and image provenance.

Price incl. GST
₹34,999
Timeline
15 working days
Deliverables
7 listed below

Overview

About this service

A cluster that works is not the same as a cluster that is safe. Out of the box, every pod can reach every other pod, containers run as root, nothing is bounded by resource limits, and secrets sit base64-encoded in etcd. We work through a running a managed container cluster, AKS or a managed container cluster and close those gaps without taking your workloads down. Changes land as manifests in your repository, so the hardened state is reviewable and reproducible rather than a set of commands somebody once ran.

Deliverables

What you receive

7 items
  1. 01 Default-deny network policies with explicit allow rules per namespace
  2. 02 RBAC review with service accounts scoped to what each workload needs
  3. 03 Pod security standards enforced, including non-root and read-only filesystems
  4. 04 CPU and memory requests and limits set from observed usage
  5. 05 Secrets moved to your cloud provider Secrets Manager or External Secrets Operator
  6. 06 Image scanning in the pipeline with a policy on critical findings
  7. 07 Findings report with residual risks and what we deliberately left alone

Benefits

Why it is worth doing

  • A compromised container can no longer roam the cluster freely

  • Noisy workloads stop starving their neighbours of CPU and memory

  • Evidence you can put in front of a customer security review

Process

How the work is carried out

  1. 1

    Baseline

    We run kube-bench and a manual review against CIS benchmarks

  2. 2

    Prioritise

    Findings ranked by exploitability and blast radius

  3. 3

    Remediate

    Changes applied namespace by namespace, staging before production

  4. 4

    Verify

    Re-scan, confirm workloads healthy, and hand over the manifests

Best suited to

  • Clusters set up quickly during a migration and never revisited
  • Teams facing a security questionnaire from an enterprise customer
  • Platforms where one compromised pod could reach the database

What we need from you

  • Cluster admin access and a staging cluster that resembles production
  • Owners for each workload, for the questions we will have about traffic
  • A change window for the network policy cutover

You can share these from your order page after checkout. The timeline starts once they are received.

FAQ

Questions about this service

We map real traffic before enforcing anything, and we roll out in audit mode first. Breakage is caught in staging.

For verification, yes, with an account you create and revoke afterwards. All changes are reviewed by you first.

No, but self-managed control planes add scope. Tell us what you run before ordering.

Have a question before you order?

Tell us about your project and we will confirm whether this service fits, or suggest a better option.

Ask about this service

This is a professional service delivered remotely; nothing is physically shipped. See the Delivery Policy and Refunds & Cancellation for how delivery, delays and refunds are handled.

Related services

You may also need

More in Cloud & DevOps

Cloud Landing Zone Setup

Your cloud environments rebuilt as versioned infrastructure as code, with separate accounts, sane networking and no click-ops left.

Timeline: 25 working days

₹44,999

GST included

CI/CD Pipeline Setup

A build, test and deploy pipeline that runs on every pull request and puts releases one click away.

Timeline: 8 working days

₹18,999

GST included

Incl. GST

₹34,999

Next step

Have something to build, fix or modernise? Start with a conversation.

Pick a service with a published scope and price, start small with a plan from ₹100, or tell our team what you need.