✓ Live now — CNCF 5 hands-on projects

CKS Hands-On Labs
Real Kubernetes Security. Real GitHub portfolio.

Five real Certified Kubernetes Security Specialist projects mapped directly to CKS exam objectives. Mark a step complete and HandsOnCert commits the evidence — Falco rules, OPA Gatekeeper policies, Trivy scan results — straight to your own GitHub repo. The portfolio employers actually click into.

$79 one-time · Project 1 free · No subscription

5
Hands-on projects
14h
Estimated time
$445
CKS exam cost
$79
HandsOnCert price

What you'll build

Every project maps to an official CKS exam domain. Each one ends with evidence committed to your GitHub repo automatically.

1

Cluster Setup and Hardening — Free

Run kube-bench CIS Kubernetes Benchmark, harden API server flags (disable anonymous auth, enable audit logging), configure default-deny NetworkPolicies, and encrypt secrets at rest in etcd. Commit your kube-bench results and hardening configurations.

Cluster Setup — 15%
2

System Hardening

Create a custom AppArmor profile and apply it to a pod via annotation, configure a seccomp profile with a syscall allowlist, and deploy pods with dropped capabilities and read-only root filesystem. Commit your AppArmor/seccomp profiles and pod security contexts.

System Hardening — 10%
3

Minimize Microservice Vulnerabilities

Enforce Pod Security Standards on a namespace, deploy OPA Gatekeeper with a custom ConstraintTemplate blocking privileged containers, and secure Kubernetes Secrets with disabled service account token automounting. Commit your Gatekeeper policies and PSS configuration.

Minimize Microservice Vulnerabilities — 20%
4

Supply Chain Security

Scan a container image with Trivy and output CRITICAL CVEs to a file, write a secure multi-stage Dockerfile with a non-root user, and configure an OPA constraint restricting images to trusted registries. Commit your Trivy scan results and secure Dockerfile.

Supply Chain Security — 20%
5

Monitoring, Logging and Runtime Security

Deploy Falco and write a custom rule detecting sensitive file access in containers, configure a Kubernetes audit policy capturing secret access and exec events, and deploy an immutable container configuration with read-only root filesystem. Commit your Falco rules and audit policy.

Monitoring, Logging & Runtime Security — 20%

Why HandsOnCert

🗂️

Real GitHub portfolio

Every completed step auto-commits evidence to your own repo. No fake portfolio templates — real configs, real screenshots, real history.

☁️

Real CNCF resources

No simulators. You work in the actual CNCF console and tools, the same ones you'll use on the job and in the CKS exam.

🤖

Cert Buddy AI mentor

Stuck on a step or an exam concept? Cert Buddy is trained on CKS objectives and helps you debug and understand — not just copy-paste.

💰

Cost alerts built in

Every chargeable resource has a clear alert telling you exactly when to stop, deallocate, or delete — so a lab break doesn't become a surprise bill.

📄

Downloadable lab guide

Get the full CKS lab guide as a PDF — step-by-step instructions, screenshots to capture, and an exam quick-reference section.

💵

One-time price

$79 once. No subscription, no recurring charges. Or get All-Access to all 21 cert paths for $199.

Frequently Asked Questions

Are the CKS hands-on labs free?

Project 1 (Cluster Hardening) is completely free, including unlimited access to Cert Buddy for that project and the manual GitHub commit workflow. The remaining 4 projects unlock for a one-time payment of $79.

Do I need CKA before CKS?

Yes. CKS requires an active CKA certification as a prerequisite — set by the Linux Foundation/CNCF, not by HandsOnCert. CKS builds directly on CKA knowledge and adds security-specific tooling on top.

What tools do the CKS labs cover?

HandsOnCert's CKS labs cover kube-bench, AppArmor, seccomp, OPA Gatekeeper, Trivy, and Falco — the same security tooling tested on the actual CKS exam, applied to real kind clusters and (for cluster hardening) an optional kubeadm-on-EC2 setup.

How does the GitHub portfolio work for CKS labs?

When you complete a lab step, HandsOnCert commits your actual Falco rules, OPA Rego policies, Trivy scan output, and hardening configurations to your own GitHub repository — a portfolio that demonstrates real platform security knowledge, which is rare and valuable to employers.

How long does the CKS path take to complete?

The 5 projects take approximately 14 hours total, covering cluster setup/hardening, system hardening, microservice vulnerabilities, supply chain security, and runtime security — the same domains tested on the CKS exam.

Is CKS the hardest Kubernetes certification?

Yes, CKS is widely considered the most difficult of the three CNCF Kubernetes certifications. It requires CKA-level knowledge plus an entirely new layer of security tooling, all under the same 2-hour performance-based exam format.

Build your CKS portfolio today

Start Project 1 free — no credit card required. See exactly how the GitHub auto-commit works before you pay anything.

Start Free →