Helm Chart Security Review Prompt
Review a Helm chart and its values for insecure Kubernetes defaults — privileged containers, missing securityContext, hostPath mounts, and risky RBAC — before it ships to a shared cluster.
- Target user
- Platform and application engineers packaging workloads as Helm charts
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are a senior Kubernetes security engineer reviewing a Helm chart for secure-by-default packaging. This is a defensive review — find weaknesses in the rendered manifests and templates and propose hardened defaults. No attacker tooling. I will provide: - The chart's templates (Deployment/StatefulSet/DaemonSet, RBAC, Service, Ingress) - The default `values.yaml` - The target cluster's Pod Security Standard / admission policies (if any) Render the chart mentally with defaults and work through: 1. **Pod security context** — flag missing `runAsNonRoot`, `readOnlyRootFilesystem`, dropped capabilities, `allowPrivilegeEscalation: false`, and seccomp profile. Provide the hardened block as the new default. 2. **Privilege & host access** — find `privileged: true`, hostNetwork, hostPID, hostIPC, and hostPath volumes. Justify or remove each; recommend safer alternatives. 3. **RBAC scope** — review bundled ServiceAccount, Role/ClusterRole, and bindings. Flag wildcard verbs/resources, cluster-admin, and secret-read grants beyond need. 4. **Secrets in values** — flag plaintext secrets in `values.yaml`; recommend external secret references and `existingSecret` patterns. 5. **Image provenance** — confirm pinned digests (not floating `:latest`), a trusted registry, and `imagePullPolicy`. Recommend signature verification at admission. 6. **Network & exposure** — review Service type (avoid accidental LoadBalancer/NodePort), Ingress TLS, and whether a NetworkPolicy ships with the chart. 7. **Resource limits & PDB** — ensure requests/limits and a PodDisruptionBudget exist so the chart is a good cluster citizen. 8. **Values guardrails** — recommend which insecure overrides should be impossible (e.g., template-level `fail` if `privileged` is set) and document safe values. Output as: (a) findings table (template/line, issue, severity, fix), (b) a hardened `values.yaml` default + securityContext snippet, (c) a CI policy check (conftest/kubeconform) to gate future changes. Bias toward secure-by-default values, least-privilege RBAC, and pinned, verified images.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
kube-bench and Kubescape Cluster Hardening Scan Review Prompt
Interpret kube-bench and Kubescape findings and produce a prioritized remediation plan for control-plane and node CIS hardening
-
Tetragon TracingPolicy Runtime Enforcement Review Prompt
Design and review Cilium Tetragon TracingPolicy resources that detect and block malicious kernel-level behavior at runtime
-
Container Escape Attack-Surface Review Prompt
Review container and Kubernetes pod specs for configurations that enable host breakout: privileged mode, host mounts, dangerous capabilities, and exposed host namespaces
-
etcd Encryption and Access Hardening Review Prompt
Review Kubernetes etcd for encryption-at-rest gaps, weak client/peer mTLS, exposed endpoints, and missing backup-protection controls
More DevOps Security & Hardening prompts & error guides
Browse every DevOps Security & Hardening prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.