Kubernetes Validation Catalog
Kubernetes Validation Catalog
Card 1 — API and RBAC boundary
Objective: confirm the supplied identity has only the documented permissions.
Preconditions: named context, cluster, namespace, identity, and test window; audit logging confirmed.
Action: record kubectl auth whoami and run kubectl auth can-i --list -n <approved-namespace>. Test one expected allow and one expected deny using kubectl auth can-i.
Evidence: context, identity, command output, API audit events, expected versus observed result.
Stop: stop if the context or identity differs from the scope record.
Card 2 — Workload admission boundary
Objective: verify policy rejects a harmless manifest that requests a prohibited setting.
Preconditions: disposable namespace and a reviewed manifest with no host mount, host networking, external image pull, secret, or persistent workload.
Action: use server-side dry run first. If the engagement permits a live admission check, submit the inert manifest and expect rejection.
Evidence: policy name, admission response, controller logs, and zero running workload confirmation.
Cleanup: delete the test object if it was accepted unexpectedly and open a finding.
Card 3 — Detection and audit coverage
Objective: prove that a benign API action is attributable from request to identity.
Action: read one approved ConfigMap or create and delete a labeled empty ConfigMap in a disposable namespace when mutation is approved.
Evidence: API audit event, actor, source, namespace, object, timestamp, and SIEM correlation.
Stop: do not proceed with broader testing if the event cannot be attributed.