ANTIPATTERNS AND VULNERABILITIES IN SECURING KUBERNETES CLUSTERS, APPROACHES TO PREVENTION
S.N. Cherkashin, I. A. Petrov · Vestnik komp iuternykh i informatsionnykh tekhnologii · 2025
The growing adoption of Kubernetes for container orchestration has intensified the need for robust security practices. This paper examines key antipatterns and vulnerabilities in securing Kubernetes clusters and proposes strategies for mitigating these risks. The focus is on evaluating traditional and modern security approaches, with an emphasis on automating security checks without compromising the performance of containerized environments. The study explores the challenges of balancing security and resource utilization in Kubernetes clusters. It discusses the limitations of deploying traditional security tools, such as antivirus software, on Kubernetes nodes, which can negatively impact system performance. The research highlights alternative security measures optimized for containerized infrastructures, such as using distroless images and immutable operating systems to reduce the attack surface. Additionally, the paper advocates for shifting security checks earlier in the development lifecycle through tools that scan container images for vulnerabilities before deployment. Automated enforcement of security policies in Kubernetes, using Validating Admission Webhooks, is explored as a method to prevent compromised images from entering production environments. The study concludes that securing Kubernetes clusters requires a multilayered approach that integrates automated tools and minimizes the performance impact. It emphasizes the need to balance security measures with operational efficiency, providing practical recommendations for achieving this in production environments.