Skip to main content

Enterprise Security Layer β€” Defense in Depth

Security is not a single tool β€” it is layered. This platform implements defense in depth: each layer assumes the previous one can be bypassed, so multiple independent controls must all fail before an attacker reaches a critical asset.


Defense in Depth Model​

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ LAYER 7 β€” GOVERNANCE & COMPLIANCE β”‚
β”‚ kube-bench (CIS) β”‚ API Audit Logs β”‚ OpenMetadata PII tags β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ LAYER 6 β€” SUPPLY CHAIN β”‚
β”‚ Cosign image signing β”‚ SBOM generation β”‚ Trivy CVE scan β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ LAYER 5 β€” RUNTIME SECURITY β”‚
β”‚ Falco (anomaly detection) β”‚ Seccomp β”‚ AppArmor profiles β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ LAYER 4 β€” POLICY ENFORCEMENT β”‚
β”‚ OPA / Gatekeeper (admission control) β”‚ NetworkPolicy (Cilium) β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ LAYER 3 β€” SECRETS MANAGEMENT β”‚
β”‚ Vault (dynamic credentials) β”‚ External Secrets Operator β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ LAYER 2 β€” AUTHORIZATION β”‚
β”‚ Kubernetes RBAC β”‚ OPA policies β”‚ Authentik roles β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ LAYER 1 β€” AUTHENTICATION β”‚
β”‚ Authentik SSO / OIDC β”‚ Service accounts β”‚ mTLS (Cilium) β”‚
β”œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ LAYER 0 β€” HOST PERIMETER βœ… β”‚
β”‚ UFW (deny all inbound) β”‚ Tailscale mesh β”‚ Cloudflare Tunnel β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Security Components Map​

ComponentLayerWhat It Does
UFWHost perimeterDefault-deny firewall on controller; blocks MAAS/Squid from public internet βœ…
Cloudflare TunnelHost perimeterPublic apps via Cloudflare β€” home IP never exposed to internet βœ…
TailscaleHost perimeterWireGuard mesh VPN β€” all admin access encrypted and authenticated βœ…
AuthentikIdentitySingle sign-on for all platform UIs; OIDC/OAuth2 + forward-auth provider (Phase 23 βœ…)
OPA / GatekeeperPolicyAdmission controller β€” blocks non-compliant workloads at deploy time
FalcoRuntimeDetects anomalous container behavior (e.g., shell in container, file read)
Cosign + SBOMSupply chainSigns images; generates bill of materials; blocks unsigned images
kube-benchComplianceRuns CIS Kubernetes benchmark; scores cluster hardening
VaultSecretsAlready in Phase 15 β€” dynamic DB passwords, PKI, secret injection
CiliumNetworkAlready in Phase 22 β€” eBPF NetworkPolicy + mTLS between pods

What Each Layer Stops​

ATTACK STOPPED BY
──────────────────────────────────────────────────────────────
Direct scan of home IP Cloudflare Tunnel hides real IP for *.devandre.sbs
MAAS/Squid exposed on IPv6 UFW default-deny: both ports now blocked
Unauthenticated admin access Tailscale: all admin paths require VPN membership
Compromised admin credentials Authentik MFA + short-lived tokens
Privilege escalation in pod OPA: no privileged containers
Image with known CVEs Trivy scan in CI (Phase 13)
Unsigned / tampered image Cosign policy in Gatekeeper
Shell spawned in running pod Falco alert + auto-kill
Data exfiltration via DNS Cilium NetworkPolicy (egress deny)
Lateral movement between pods Cilium NetworkPolicy (namespace isolation)
Leaked DB password in config Vault: dynamic credentials, no static secrets
CIS benchmark failures kube-bench + remediation runbook
PII data accessed by wrong team OPA row-level + OpenMetadata PII tags

Platform Security Contacts​

Each team owns the security of their namespace. Platform security team owns:

AreaContact / Runbook
SSO / identity incidentsPlatform team β†’ Authentik admin (https://auth.10.0.0.200.nip.io)
Active intrusion (Falco alert)On-call β†’ incident runbook
CVE in production imageDev team β†’ patch + redeploy within SLA
Compliance auditPlatform team β†’ kube-bench report

Security Scanning Pipeline (CI/CD Integration)​

git push
↓
GitLab CI build stage
↓
Trivy scan (CRITICAL exit-code 1)
↓
Cosign sign image (if scan passes)
↓
Syft SBOM attach to image
↓
Harbor stores image + SBOM + signature
↓
Gatekeeper admission check (signature required)
↓
Deploy to cluster

Quick Security Health Check​

# Check Falco alerts in last hour
kubectl logs -n falco daemonset/falco --since=1h | grep -E "WARNING|CRITICAL"

# Check Gatekeeper constraint violations
kubectl get constraintviolations -A

# Check kube-bench score
kubectl logs -n kube-bench job/kube-bench | tail -20

# Check for privileged pods (should be 0)
kubectl get pods -A -o json | jq '.items[] | select(.spec.containers[].securityContext.privileged == true) | .metadata.name'

# Check for pods with no resource limits
kubectl get pods -A -o json | jq '.items[] | select(.spec.containers[].resources.limits == null) | .metadata.name'

Done When​

βœ” UFW enabled on controller β€” MAAS and Squid blocked from public internet (2026-06-21 βœ…)
βœ” Cloudflare Tunnel β€” home IP hidden for all *.devandre.sbs traffic (Phase 25 βœ…)
βœ” Tailscale β€” all admin access via WireGuard mesh (Phase 3 βœ…)
βœ” Authentik SSO active β€” apps on SSO (Phase 23 βœ…); MAAS deferred
βœ” OPA Gatekeeper blocking privileged / no-resource-limit pods
βœ” Falco alerting on shell-in-container and unexpected file access
βœ” All production images signed with Cosign + SBOM attached
βœ” kube-bench score β‰₯ 80% on all CIS checks
βœ” Zero static DB passwords in Kubernetes secrets (all via Vault)
βœ” NetworkPolicy isolating namespaces (Cilium)