Kubernetes security misconfigurations identified and fixed with AI models
Kubernetes Misconfigurations in the Wild: Taxonomy, Evolution, and Automated Repair with Large Language Models
Software Engineering
Summary
Kubernetes is software that helps run applications in the cloud, but setting it up can cause security mistakes that make systems unsafe. The authors studied many real problems reported by developers online to find common security errors and see how they change over time. They tested large language models (AI that understands and writes code) to automatically fix these mistakes and created a tool to check fixes against official rules. Together, the AI and the tool corrected nearly all errors while avoiding new ones, helping make Kubernetes setups safer.
What this means in practice
- •For cloud platform engineers: Automatically detect and fix security mistakes in Kubernetes configurations during application deployment to improve reliability and safety.
- •For devops teams: Use AI-powered tools combined with schema checks to reduce manual troubleshooting of Kubernetes security errors, speeding up maintenance workflows.
Authors
Mostafa Anouar Ghorab, Ahmad Abdel Latif, Mohamed Aymen Saied
Abstract
Kubernetes is widely used to orchestrate cloud-native applications, yet its declarative configuration model often introduces security misconfigurations that threaten system reliability. Despite available detection tools, misconfiguration patterns and scalable remediation remain insufficiently understood. This paper presents an empirical study of Kubernetes security misconfigurations based on 2,662 developer-reported Stack Overflow issues. We derive a taxonomy of recurring security weaknesses across configuration objects and categories. We analyze severity variations and investigate how misconfigurations evolve between incubator and stable project stages. Findings show that while some operational issues decrease as projects mature, critical security misconfigurations often persist or reappear. We then evaluate Large Language Models (LLMs) for automated remediation under progressively enriched contextual conditions. Contextual grounding improves correction accuracy, with the best standalone model achieving 89.06%. To enhance structural correctness and schema compliance, we introduce Kubecurity, a schema-guided validation framework based on official Kubernetes specifications. Combining contextual LLM reasoning with deterministic schema enforcement achieves 98.50% correction accuracy while substantially reducing newly introduced misconfigurations. This work advances the understanding of Kubernetes security misconfigurations and demonstrates a hybrid approach to more reliable automated remediation.