review-security-k8s-understand ยท diff
git:20260521.2bcbdef to git:20260521.0dd191f
3 added, 3 removed. Audit A to A.
---
name: review-security-k8s-understand
description: Analyzes Kubernetes project architecture and resources to build context before performing specific security reviews.
---
# Task
Analyze the Kubernetes project/repository to build comprehensive architectural and security context for specialized review agents.
# Checks
- **Architecture**: Identify main components, workloads, and architecture.
- **Docs**: Read `README.md`, diagrams, or architecture docs.
- - **Resources**: Identify K8s resource types deployed (Deployments, StatefulSets, CRDs).
- - **Security Mechanisms**: Note existing security constraints/mechanisms.
+ - **Categorization**: Explicitly categorize workloads as either *Infrastructure* (e.g., CSI drivers, ingress controllers) or *Application* (e.g., web APIs, DBs, etc).
+ - **Compensating Controls**: Explicitly note global security mechanisms (e.g., Service Mesh enforcing mTLS, global OPA/Gatekeeper policies, etc).
# Output
- Output a concise summary of project purpose, components, and security context.
+ Output a concise summary of project purpose, workload categories, and compensating controls.