Skip to content
Scope, price and timeline published on every engagement page Engineers assigned within 3 working days of kickoff Your repositories, cloud accounts and licences stay in your name
Cloud & DevOps Fixed scope

Kubernetes Cluster Hardening Sprint

We close the default gaps in a running cluster: network policy, RBAC, resource limits, secrets and image provenance.

Delivered in

15 working days

Revisions

One round, included

Ownership

Yours from day one

Overview

What this engagement is

A cluster that works is not the same as a cluster that is safe. Out of the box, every pod can reach every other pod, containers run as root, nothing is bounded by resource limits, and secrets sit base64-encoded in etcd. We work through a running EKS, AKS or GKE cluster and close those gaps without taking your workloads down. Changes land as manifests in your repository, so the hardened state is reviewable and reproducible rather than a set of commands somebody once ran.

Deliverables

What lands in your repositories

7 items
  • Default-deny network policies with explicit allow rules per namespace
  • RBAC review with service accounts scoped to what each workload needs
  • Pod security standards enforced, including non-root and read-only filesystems
  • CPU and memory requests and limits set from observed usage
  • Secrets moved to AWS Secrets Manager or External Secrets Operator
  • Image scanning in the pipeline with a policy on critical findings
  • Findings report with residual risks and what we deliberately left alone

Outcomes

What changes once it ships

A compromised container can no longer roam the cluster freely

Noisy workloads stop starving their neighbours of CPU and memory

Evidence you can put in front of a customer security review

Process

How the 4 stages run

  1. 01

    Baseline

    we run kube-bench and a manual review against CIS benchmarks

  2. 02

    Prioritise

    findings ranked by exploitability and blast radius

  3. 03

    Remediate

    changes applied namespace by namespace, staging before production

  4. 04

    Verify

    re-scan, confirm workloads healthy, and hand over the manifests

Booked most often by

  • Clusters set up quickly during a migration and never revisited
  • Teams facing a security questionnaire from an enterprise customer
  • Platforms where one compromised pod could reach the database

What we need from you

  • Cluster admin access and a staging cluster that resembles production
  • Owners for each workload, for the questions we will have about traffic
  • A change window for the network policy cutover

These are collected in the technical brief that opens in your dashboard the moment payment clears. The clock starts when they arrive, not before.

Answers

Questions this engagement raises

We map real traffic before enforcing anything, and we roll out in audit mode first. Breakage is caught in staging.

For verification, yes, with an account you create and revoke afterwards. All changes are reviewed by you first.

No, but self-managed control planes add scope. Tell us what you run before ordering.

This is engineering work, not a physical product — nothing ships and there is no stock to run out of. Delivery is to the working days stated above, into systems you control, and the refund terms set out what happens if we miss the date.

Booked alongside

Engagements that pair with this one

All Cloud & DevOps
Cloud & DevOps Most booked

Terraform AWS Landing Zone

Your AWS environments rebuilt as versioned Terraform, with separate accounts, sane networking and no click-ops left.

Terraform modules for VPC, subnets, security groups, IAM and core services
25 working days Scope published

Fixed fee · GST incl.

₹44,999

GitHub Actions CI/CD Setup

A build, test and deploy pipeline that runs on every pull request and puts releases one click away.

CI workflow running lint, unit tests and build on every pull request
8 working days Scope published

Fixed fee · GST incl.

₹18,999

AWS Cost Reduction Audit

We read your AWS bill line by line and hand back a ranked list of savings with the risk of each one stated.

Line-by-line analysis of three months of AWS spend
6 working days Scope published

Fixed fee · GST incl.

₹12,999

GST included

₹34,999

Capacity open this month

Read the scope. Know the price. Start on Monday.

No discovery calls to find out a number, no statements of work that take three weeks to sign. Pick the engagement that matches the problem and we assign the engineers.