Services Methodology Why Us About Us Blog Get in Touch
← Back to Services
// 09 — CONTAINERISATION

Containerisation
Security Reviews

Docker and Kubernetes security assessment covering image vulnerabilities, cluster misconfigurations, privilege escalation paths, and network policy weaknesses across the full container lifecycle.

DockerKubernetesImage ScanningRBAC ReviewNetwork PoliciesPod SecurityRuntime SecurityHelm
Overview

Container environments introduce unique security challenges — misconfigured Kubernetes RBAC, privileged containers, exposed API servers, and vulnerable base images can all lead to cluster-wide compromise or host escape. Our reviews assess the full stack, from Dockerfile to running cluster configuration.

We combine automated scanning with manual adversarial testing — attempting to escape containers, escalate within the cluster, and pivot to underlying infrastructure where misconfigurations permit. This gives you evidence of real-world exploitability, not just theoretical risk.

Container security is a fast-moving space. Our experienced operators stay current with the latest Kubernetes CVEs, escape techniques, and cluster attack paths — ensuring your assessment reflects the current threat landscape.

Testing Methodology
01

Image & Registry Security

Scanning of container images for known CVEs using industry-standard scanners and apps. Review of base image selection, image layering, non-root user enforcement, unnecessary packages, and registry access controls including public image exposure.

02

Dockerfile & Build Security

Static review of Dockerfiles for secrets baked into layers, over-privileged build processes, multi-stage build security, and insecure base image choices. Assessment of build pipeline security, image signing, and supply chain integrity.

03

Kubernetes Cluster Configuration

Assessment of kube-apiserver exposure, anonymous authentication, insecure admission controllers, audit logging, etcd encryption, and cluster-level security settings against security best practices, including CIS Kubernetes benchmarks and more.

04

RBAC & Service Account Review

Analysis of Role and ClusterRole bindings, over-permissive service accounts, default service account token automounting, and token projection. We identify privilege escalation paths through RBAC misconfigurations and service account abuse.

05

Network Policy & Segmentation

Review of Kubernetes NetworkPolicy objects, ingress controller configurations, and pod-to-pod communication restrictions. We identify flat network configurations that allow unconstrained lateral movement between namespaces and workloads.

06

Runtime Security & Secrets Management

Assessment of secrets management (Kubernetes Secrets encryption, Vault integration), runtime security tooling (Falco, AppArmor, Seccomp profiles), Pod Security Standards enforcement, and node-level security configuration.

07

Reporting & Remediation

Findings mapped to relevant Kubernetes benchmarks and controls, with examples provided to accelerate remediation. Debrief call with your platform engineering team included.

What Makes Levantis Different

We test containers the way attackers do — attempting to escape, escalate, and pivot. Every identified misconfiguration is validated for exploitability, so you understand which findings represent real risk in your environment.

We provide practical configuration examples and remediation guidance directly in the report, giving your platform team everything they need to implement fixes efficiently without weeks of additional research.

// Common Findings

  • Privileged containers
  • Host path volume mounts
  • Over-permissive ClusterRoles
  • Exposed kube-apiserver
  • Missing NetworkPolicies
  • Secrets in environment vars
  • Root user in containers
  • Unencrypted etcd

// Standards

  • CIS Kubernetes Benchmark
  • NSA/CISA Kubernetes Hardening
  • Pod Security Standards (PSS)
  • NIST SP 800-190

// Typical Duration

  • Image & config review: 3–5 days
  • Full cluster assessment: 5–8 days
  • With adversarial testing: 8–12 days

// Engage Us

Ready to scope an engagement? Get in touch for a no-obligation conversation.

Get in Touch

Secure your containers from image to runtime.

Container misconfigurations are pervasive and often overlooked. Our specialist assessment covers the full stack — from Dockerfile to live cluster.

Get in Touch