I will harden and secure your kubernetes cluster and docker containers

Vetted Pro

Brazil

I speak English, Portuguese, Spanish, French

11 orders completed

Lead Security Architect for Hybrid Cloud, IAM and Zero Trust

Lead Security Architect, 14+ years across banks, telecom and large enterprises, ex-IBM and TOTVS. Most clients know something is wrong but not where. I find it, then I design what replaces it and the...
Vetted by Fiverr Pro

Marlon Costa was selected by the Fiverr Pro team for their expertise.

Vetted for

  • Cloud Computing

  • Cybersecurity

  • Data Governance & Protection

  • DevOps Engineering

  • Regulatory Compliance Consulting

  • Support & IT

About this Gig

Vetted Pro

Your cluster works. That is not the same as your cluster being safe.


Kubernetes ships wide open and most clusters are close to default. Everything runs, so nobody looks, until a customer asks or a pen test comes back.


You are probably here because

  • A customer or auditor asked how you isolate workloads
  • Containers run as root because that was the only way to ship
  • Every pod can reach every pod and nobody meant that


What I change

  • RBAC cut from cluster-admin to what each workload needs
  • Root and privileged containers removed, Pod Security enforced
  • Network policies, so pods stop reaching pods they should not
  • Secrets out of ConfigMaps, image scanning in the build


How it works

  1. You tell me what you run and we agree a change window
  2. I apply changes in stages, validate each, log every one
  3. You get the documentation, rollback path and a walkthrough


What you can count on

Every change reversible, in a window you choose, tested in staging first.


Works with

EKS, GKE, AKS, OpenShift, self-managed, Docker, Helm, Terraform.

Hardened against CIS Kubernetes, NIST SP 800-190 and OWASP K8s Top 10.


Tell me what you run and I will say which fits.

Tools:

Kubernetes

•

Docker

•

OpenShift

•

Amazon EKS

Frameworks:

Npm

•

Terraform

•

Ansible

•

Puppet

•

SaltStack

Cloud Provider:

Amazon Web Services

•

Microsoft Azure

Programming language:

Bash

•

C

•

Java

•

JavaScript

•

Kotlin

•

PHP

•

Python

•

Ruby

Expertise:

Installation

•

Debugging

•

Configuration

My Portfolio

Other DevOps Engineering Services I Offer

Related tags