Skip to content
All services
Container platformsAssess

Container platform check

A one-week, read-only review of your Kubernetes clusters or serverless container runtime, with evidence for every finding, a hardening plan ordered by risk and a readout with your team.

When you need it

Your services moved to containers faster than the guardrails around them. Nobody can say for sure which workloads can reach each other, which ones hold broad cloud permissions or whether an unscanned image could reach production.

What sets the quote

  • Either up to 3 Kubernetes clusters (EKS, AKS, GKE or OpenShift) or one serverless runtime (ECS on Fargate, Azure Container Apps, Azure Container Instances or Cloud Run), in up to 2 regions.
  • Up to 20 services or jobs in total, one image registry (Amazon ECR, Azure Container Registry or Artifact Registry) and one CI/CD system, such as GitHub Actions, GitLab CI/CD or Azure Pipelines.
  • Read-only access throughout, so nothing in your environment changes during the check.
  • Sized from counts you send us (clusters, services and jobs, regions), taken with a read-only kubectl command or inventory query that we provide.
  • More clusters, services or regions, or a second platform, are quoted after sizing.

What changes

  • You know which workloads can reach each other, which cloud permissions each one holds and which images reach production unchecked.
  • Every finding comes with evidence and the affected clusters or services, so your team can act without investigating again.
  • You have a hardening plan ordered by risk and effort, ready for your backlog.

What you get

  • Findings report with severity, affected clusters or services, evidence and the fix
  • CIS benchmark results for each Kubernetes cluster, pass or fail per control
  • Hardening plan ordered by risk and effort, including the upgrade path for each cluster
  • All findings as a CSV file for your ticket system
  • A 90-minute readout with your team

What we cover on each platform

PlatformWhat we check
Kubernetes (EKS, AKS, GKE, OpenShift)The CIS benchmark for your distribution; RBAC; Pod Security Standards (Security Context Constraints on OpenShift); network policies; workload identity (EKS Pod Identity or IRSA, Microsoft Entra Workload ID, Workload Identity Federation for GKE); secrets; image admission policy; version and upgrade posture
ECS on FargateTask roles and task execution roles; secrets from Secrets Manager or Systems Manager Parameter Store; security groups; load balancer and TLS; ECR image scanning; logs; autoscaling; deployment circuit breaker
Azure Container Apps and Container InstancesManaged identity; VNet integration; ingress; private access to ACR; Defender for Containers; in Container Apps, also internal environments, Key Vault references, revisions, traffic splitting and scale rules
Cloud RunA dedicated service account per service; ingress settings; Direct VPC egress; Binary Authorization; Secret Manager; Artifact Registry scanning; CMEK; invoker permissions; instance and concurrency settings

Not included

  • Fixing the findings (quoted separately, often as a serverless container platform or Kubernetes platform package)
  • The cloud foundation around the platform, which the cloud foundation check covers
  • Application code review
  • Penetration testing (we can refer you to a certified partner)

What we need from you

  • AWS: SecurityAudit and ViewOnlyAccess in the accounts that run the platform.
  • Azure: Reader and Security Reader on the subscriptions that run the platform.
  • Google Cloud: Viewer and Security Reviewer on the projects that run the platform.
  • Kubernetes: a read-only cluster role that we supply, which can see workloads, RBAC and policies but not secret values.
  • Read access to your CI/CD system, and two 60-minute interviews: your platform owner and a lead developer.

How it works

  1. Free 30-minute call, then the sizing counts and a written fixed quote.

  2. Automated scans with read-only access, plus a manual review of identity, network, secrets, images and the release path.

  3. Interviews to confirm context and priorities.

  4. Findings report, hardening plan and a 90-minute readout.

At a glance

Duration
1 week
Price
Fixed quote after a free 30-minute call
Delivered by
Our lead architect
Build Popular

Serverless container platform

A platform for your containerised services on ECS on Fargate, Azure Container Apps or Google Cloud Run in 3–7 weeks, built as code with one reusable service module for every team.

Duration:3–7 weeks
Build Popular

Kubernetes platform

A Kubernetes platform on EKS, AKS, GKE or managed OpenShift in 5–6 weeks, run through GitOps, with access, policies, secrets and scaling in place and your first services onboarded.

Duration:5–6 weeks

Not sure where to start?

Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.