Skip to content

Security Hardening

Killercoda lab progress 0/4 completed

Interactive labs, not module completion

Protecting Linux systems and containers through kernel-level security.

Security isn’t just firewalls—it’s defense in depth. This section covers the Linux security mechanisms that protect containers and hosts: kernel tuning, mandatory access controls (AppArmor, SELinux), and system call filtering (seccomp).

#ModuleDescriptionTime
4.1Kernel Hardening & sysctlNetwork stack, memory protection, kernel parameters70–100 min
4.2AppArmor ProfilesMandatory access control, profile modes, K8s integration80–110 min
4.3SELinux ContextsPolicies, contexts, enforcing mode, troubleshooting80–110 min
4.4seccomp ProfilesSystem call filtering, custom profiles80–110 min

These are planning estimates copied from the four module headers, not measured learner completion times. Their arithmetic gives an aggregate range of 310–430 minutes (about 5 hours 10 minutes–7 hours 10 minutes); individual setup, reading, and practice time will vary.

Linux security features are directly used by Kubernetes:

  • sysctl — Node hardening, network security
  • AppArmor — Pod security profiles (Ubuntu/Debian)
  • SELinux — Pod security profiles (RHEL/CentOS)
  • seccomp — System call filtering for containers

CKS (Certified Kubernetes Security Specialist) specifically tests these topics.

After completing this section, you’ll understand:

  1. How to harden Linux kernels via sysctl
  2. How AppArmor profiles restrict application behavior
  3. How SELinux provides mandatory access control
  4. How seccomp filters dangerous system calls