Hardening cert-manager and Kyverno in Sensitive Kubernetes Clusters

cert-manager and Kyverno are widely-deployed open source tools that help secure a production cluster; however, both operate at a highly privileged level, and misconfigurations can inadvertently create direct paths for unauthorised access, data exfiltration, and the potential for a full cluster compromise.
To address these risks, ControlPlane collaborated with the Cloud Native Computing Foundation (CNCF) and the Linux Foundation to launch two comprehensive resources for platform operators and security teams: the cert-manager End User Threat Model and Hardening Guide and the Kyverno End User Threat Model and Hardening Guide.
These guides are built on top of ControlPlane’s tried-and-tested threat modelling process, previously featured in the ArgoCD and Envoy projects, as well as in work with our highly regulated clients. We draw on our deep industry expertise and experience working with highly regulated companies to build out assurance documents and dive deep into the product documentation, technical details, and human-driven organisational risks to create a threat model that reflects the true risk of running these workloads in production, highlighting common misconfigurations and “sharp edges”.
We then break down each of these risks into consumable, human-readable chunks and explain optimal mitigation options, so that no matter how you’re deploying cert-manager or Kyverno, you know you are following best-in-industry practices.
The importance of cert-manager and Kyverno in the AI era
As businesses increasingly adopt AI workloads and agents, the attack surface associated with non-human identities (NHI) continues to grow. Securing the identities that power these systems has become a significant security challenge. Therefore, issuing secure identities for these workloads using certificates with cert-manager is more important than ever.
Furthermore, as recently demonstrated by the OpenAI & Hugging Face hack, even leading organisations struggle to enforce strong Kubernetes hardening. Kyverno helps bridge that gap by enforcing secure settings at deployment time, preventing insecure workloads from being admitted to the Kubernetes control plane.
The urgency of this hardening is highlighted by industry data:
- 79% of organisations predict exponential growth in machine identity-related incidents, with 34% specifically involving API keys and SSL/TLS certificates (CyberArk).
- Credential targeting remains a primary attack vector in the AI era (2026 Thales Data Threat Report).
The cert-manager End User Threat Model and Hardening Guide
To help cert-manager end users secure their deployments, this guide offers a comprehensive, threat-model-driven blueprint for operating cert-manager and its supporting components securely in production. The guide rigorously identifies operational risks and common misconfigurations not typically captured by traditional penetration testing.
The guide spans critical security domains, offering deep dives into risks related to:
- PKI Architecture and Key Management
- RBAC and Access Control
- Network Isolation and Multi-tenant Security
- Secret Storage and Certificate Lifecycle Management
To address the identified threats, the guide provides practical hardening recommendations for cluster operators, platform engineers, and security teams.
Securing Policy Enforcement with Kyverno
Kyverno functions as a critical security control plane, meaning its operational integrity is inseparable from a cluster’s overall security posture. Understanding Kyverno’s trust boundaries and operational failure modes is essential for preventing governance bypasses.
The guide assists those running or planning to run Kyverno in production and establishes a shared baseline for how the community evaluates Kyverno threats. The guide highlights how a layered approach to mitigations can reduce overall risk, with a key focus on:
- Policy integrity and supply chain
- RBAC and Access Control
- Secrets and key management
- Reporting and observability
Next Steps
Review the detailed recommendations by reading the cert-manager End User Threat Model and Hardening Guide and downloading the Kyverno End User Threat Model and Hardening Guide PDF.
Contact the ControlPlane team to see how we operationalise human-centric security for the world’s most sensitive organisations and data flows, and evaluate and secure your cloud native control plane.
Related blogs

Sovereign Signing: A Self-Hosted Supply Chain with OpenBao, Cosign, and Flux CD

The Quantum Leap: Navigating PQC Adoption in Today's Digital Infrastructure
