A Multi-Layer Zero Trust Security Framework for Kubernetes
Abstract
Kubernetes is a powerful container orchestration platform. However, its clustered nature expands the attack surface across workload identity, runtime security, network, and secret management layers. Existing Zero Trust solutions for Kubernetes are layer-specific, creating opportunities for attackers to bypass one control and exploit weaknesses in another. This fragmented approach fails to protect the entire Kubernetes stack. This research proposes and evaluates a multi-layer Zero Trust architecture framework for Kubernetes that integrates Kyverno, Cilium, SPIFFE/SPIRE, HashiCorp Vault, and Falco into a single, policy-deconflicted enforcement stack. The framework was tested against three attack scenarios targeting different layers: hardcoded secret injection, cross-namespace lateral movement, and runtime shell execution inside a container. The experimental results show the framework prevented or detected all three attacks. Kyverno blocked insecure manifests at admission time with a 100% enforcement rate, Cilium dropped every unauthorized cross-namespace connection attempt within 50 ms, and Falco detected shell access with an average Mean Time To Detect (MTTD) of 66.73±4.15 seconds. The total system overhead remained low, with peak CPU usage at 12.6% and memory consumption around 290 MB across all components. This confirms cross-layer integration is essential and demonstrates that a multi-layer Zero Trust framework is both effective and practical for Kubernetes environments.