Dexfense

Know your attack surface.Build your defense.

Map your system architecture to MITRE ATT&CK® and get a prioritised, exportable security defense plan — in minutes.

MITRE ATT&CK® mapped 70+ components covered NIST CSF 2.0 Gap Analysis Exportable PDF reports
70+ Security Components
200+ ATT&CK® Techniques
NIST CSF 2.0 Aligned
Free to Use
HomeCommunity LibraryKubernetes-Hosted Application

Kubernetes-Hosted Application

Dexfense Reviewed

Container-orchestrated microservices on Kubernetes with a service mesh, CI/CD pipeline, RBAC and centralised logging.

Cloud & SaaSEnterprise
15 components·By Dexfense·v1.0 · July 2026

Overview

Covers a production microservices workload running on a managed Kubernetes cluster (EKS, GKE or AKS). Includes containerised application services, a service mesh for mTLS between pods, a managed ingress controller and load balancer, SQL and NoSQL databases, OAuth/OIDC authentication, MFA for administrative access, a GitOps CI/CD pipeline, infrastructure-as-code, cloud object storage, centralised logging and SIEM integration.

Intended for

Platform engineers, DevSecOps teams and security architects responsible for Kubernetes environments.

Architecture Assumptions

This template assumes the following conditions. If your environment differs, use Remix to adapt the component selection.

  • Cluster is hosted on a managed Kubernetes service with a hardened control plane
  • RBAC is enforced within the cluster; no wildcard permissions are granted
  • Container images are scanned for CVEs before deployment to the registry
  • Kubernetes Network Policies segment namespaces; pods cannot communicate freely
  • All inter-service traffic is encrypted via service mesh mTLS

Out of Scope

  • Host-level OS security for Kubernetes nodes is not modelled
  • Admission controllers and OPA/Kyverno policy definitions are not assessed
  • Assumes no privileged containers or hostPath volume mounts in production workloads
  • Supply-chain security of base images is noted but not deeply analysed

Architecture Components15 components selected

Containers

Kubernetes

Container orchestration platform

Containers

Containerized applications and services

Service Mesh

Service-to-service communication infrastructure

Web & APIs

API Services

API endpoints for application integration

Databases

SQL Databases

Relational databases holding structured data

NoSQL Databases

Non-relational databases for unstructured data

Network

Load Balancers

Traffic distribution systems

Auth & IAM

OAuth/OIDC

Open authorization and identity protocols

Multi-Factor Auth

Additional authentication verification layer

Monitoring

Logging Systems

Centralized log collection and management

SIEM

Security Information and Event Management

DevOps

CI/CD Pipeline

Continuous Integration/Continuous Deployment pipeline

Source Control

Version control systems (Git, SVN)

IaC

Infrastructure as Code (Terraform, CloudFormation)

Storage

Cloud Storage

Cloud-based object or file storage

Security Preview

Based on this architecture's component selection

Indicative Risk Score

61/100

13 techniques identified

2 Critical · 3 High

Top Attack Techniques

  • CriticalT1068Exploitation for Privilege Escalation
  • CriticalT1486Data Encrypted for Impact
  • HighT1190Exploit Public-Facing Application
  • HighT1574Hijack Execution Flow
  • HighT1072Software Deployment Tools

Top Recommended Controls

  • 1Implement Web Application Firewall (WAF) and regular security testing
  • 2Adopt container security best practices including least privilege access and network policies
  • 3Focus on Data Protection as your highest priority security initiative

The full defense plan — mitigations, detection methods, NIST CSF 2.0 mapping and exportable report — is available when you use this architecture in the planner.

Use This ArchitectureRemix This Architecture

Remix copies the components so you can add or remove items before generating your assessment.

Dexfense does not scan your systems. This template identifies threats and controls relevant to this architecture. Product and version validation is still required.

Back to Community Library