Kubernetes Validation Catalog

Kubernetes Validation Catalog

Card 1 — API and RBAC boundary

Objective: confirm the supplied identity has only the documented permissions.

Preconditions: named context, cluster, namespace, identity, and test window; audit logging confirmed.

Action: record kubectl auth whoami and run kubectl auth can-i --list -n <approved-namespace>. Test one expected allow and one expected deny using kubectl auth can-i.

Evidence: context, identity, command output, API audit events, expected versus observed result.

Stop: stop if the context or identity differs from the scope record.

Card 2 — Workload admission boundary

Objective: verify policy rejects a harmless manifest that requests a prohibited setting.

Preconditions: disposable namespace and a reviewed manifest with no host mount, host networking, external image pull, secret, or persistent workload.

Action: use server-side dry run first. If the engagement permits a live admission check, submit the inert manifest and expect rejection.

Evidence: policy name, admission response, controller logs, and zero running workload confirmation.

Cleanup: delete the test object if it was accepted unexpectedly and open a finding.

Card 3 — Detection and audit coverage

Objective: prove that a benign API action is attributable from request to identity.

Action: read one approved ConfigMap or create and delete a labeled empty ConfigMap in a disposable namespace when mutation is approved.

Evidence: API audit event, actor, source, namespace, object, timestamp, and SIEM correlation.

Stop: do not proceed with broader testing if the event cannot be attributed.