Kubernetes-Hosted Application
Dexfense ReviewedContainer-orchestrated microservices on Kubernetes with a service mesh, CI/CD pipeline, RBAC and centralised logging.
Overview
Covers a production microservices workload running on a managed Kubernetes cluster (EKS, GKE or AKS). Includes containerised application services, a service mesh for mTLS between pods, a managed ingress controller and load balancer, SQL and NoSQL databases, OAuth/OIDC authentication, MFA for administrative access, a GitOps CI/CD pipeline, infrastructure-as-code, cloud object storage, centralised logging and SIEM integration.
Intended for
Platform engineers, DevSecOps teams and security architects responsible for Kubernetes environments.
Architecture Assumptions
This template assumes the following conditions. If your environment differs, use Remix to adapt the component selection.
- Cluster is hosted on a managed Kubernetes service with a hardened control plane
- RBAC is enforced within the cluster; no wildcard permissions are granted
- Container images are scanned for CVEs before deployment to the registry
- Kubernetes Network Policies segment namespaces; pods cannot communicate freely
- All inter-service traffic is encrypted via service mesh mTLS
Out of Scope
- Host-level OS security for Kubernetes nodes is not modelled
- Admission controllers and OPA/Kyverno policy definitions are not assessed
- Assumes no privileged containers or hostPath volume mounts in production workloads
- Supply-chain security of base images is noted but not deeply analysed
Architecture Components15 components selected
Containers
Kubernetes
Container orchestration platform
Containers
Containerized applications and services
Service Mesh
Service-to-service communication infrastructure
Web & APIs
API Services
API endpoints for application integration
Databases
SQL Databases
Relational databases holding structured data
NoSQL Databases
Non-relational databases for unstructured data
Network
Load Balancers
Traffic distribution systems
Auth & IAM
OAuth/OIDC
Open authorization and identity protocols
Multi-Factor Auth
Additional authentication verification layer
Monitoring
Logging Systems
Centralized log collection and management
SIEM
Security Information and Event Management
DevOps
CI/CD Pipeline
Continuous Integration/Continuous Deployment pipeline
Source Control
Version control systems (Git, SVN)
IaC
Infrastructure as Code (Terraform, CloudFormation)
Storage
Cloud Storage
Cloud-based object or file storage
Security Preview
Based on this architecture's component selection
Indicative Risk Score
61/100
13 techniques identified
2 Critical · 3 High
Top Attack Techniques
- CriticalT1068Exploitation for Privilege Escalation
- CriticalT1486Data Encrypted for Impact
- HighT1190Exploit Public-Facing Application
- HighT1574Hijack Execution Flow
- HighT1072Software Deployment Tools
Top Recommended Controls
- 1Implement Web Application Firewall (WAF) and regular security testing
- 2Adopt container security best practices including least privilege access and network policies
- 3Focus on Data Protection as your highest priority security initiative
The full defense plan — mitigations, detection methods, NIST CSF 2.0 mapping and exportable report — is available when you use this architecture in the planner.
Remix copies the components so you can add or remove items before generating your assessment.
Dexfense does not scan your systems. This template identifies threats and controls relevant to this architecture. Product and version validation is still required.