Contents

Overview

UEFI Secure Boot

Firewall Management

Certificate Management

Cert Manager

Cert-Manager Post Installation Setup

Locally creating certificates

User Management

Introduction

Reference Material

Auditing

Container Image Integrity (Signature Validation)

Container AppArmor Profile

Encrypting Data at Rest

Vault Secret and Data Management

IPsec on Management Network

Secure Inter-host Pod-to-pod Network Traffic

CVE Maintenance

Security Feature Configuration for Spectre and Meltdown

Deprecated Functionality

Appendix: Configurations for CIS benchmark