
Hari 36: OPA Policy Testing — Deny vs Allow
Test Gatekeeper policy: Pod tanpa resources ditolak (4 violations), Pod dengan resources diterima. Surprise: K8s auto-fill requests dari limits sebelum webhook dipanggil.

Hari 35: Rego Policy Pertama — Wajib Resource Limits
Tulis Rego policy pertama untuk Gatekeeper: Pod/Deployment tanpa resource limits dan requests ditolak. 4 violation rules, enforcementAction deny, 0 violations.

Hari 34: Install OPA Gatekeeper — Bouncer K8s Cluster
OPA Gatekeeper terinstall sebagai admission controller di k3d cluster. 2 pods running, 17 CRDs, validating webhook aktif. Besok tulis Rego policy pertama.

Hari 33: SecurityContext Hardening — 20 Temuan ke 0
Deployment.yaml di-hardened: non-root, read-only filesystem, cap drop ALL, probes, resources. 3 scanner: Kubesec 0→11, Checkov 20→0, Trivy 16→0. Pods tetap running.

Hari 32: Scan K8s Misconfig — 3 Scanner, 20+ Temuan
Kubesec, Checkov, Trivy scan deployment.yaml yang sengaja insecure. Hasilnya: 14 advise, 20 failed, 16 findings. Ini perbandingan POV 3 scanner K8s.

Hari 31: Deploy SecureBank API ke Kubernetes dengan k3d
Fase 3 dimulai! Bikin k3d cluster lokal, deploy distroless image 7.97MB ke K8s dengan secret. 2 replicas running, endpoint tested.
Page 3 of 8 • 48 articles