Cloud / CNAPP · Reference Architecture
Kubernetes Security Architecture
Layered security for cluster control planes, workload identity, admission, supply chain, runtime, network, secrets and operational recovery.
SECUREPLANE REFERENCE MODELKubernetes Security Architecture
Platform ownership · workload ownership
01SOURCEcode · IaC
02BUILDSBOM · sign
03ADMITpolicy · provenance
04RUNidentity · network
05OBSERVEruntime · evidence
Golden paths · exceptions · recovery
Which controls protect the platform without making delivery or recovery unmanageable?
Representative outputs
Artifacts that make the decision usable
No diagram is a deployable design until it is adapted to the environment, evidence, owners, and operating constraints.
Kubernetes security reference architectureResponsibility modelAdmission policy designSupply-chain controlsRuntime and recovery playbook