Kubernetes Misconfigurations in the Wild: Taxonomy, Evolution, and Automated Repair with Large Language Models

📅 2026-09-22
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
研究解决了Kubernetes安全配置错误问题,通过分析2,662个Stack Overflow问题构建分类体系,并使用大语言模型结合模式引导框架Kubecurity进行自动修复。
📝 Abstract
Kubernetes is widely used to orchestrate cloud-native applications, yet its declarative configuration model often introduces security misconfigurations that threaten system reliability. Despite available detection tools, misconfiguration patterns and scalable remediation remain insufficiently understood. This paper presents an empirical study of Kubernetes security misconfigurations based on 2,662 developer-reported Stack Overflow issues. We derive a taxonomy of recurring security weaknesses across configuration objects and categories. We analyze severity variations and investigate how misconfigurations evolve between incubator and stable project stages. Findings show that while some operational issues decrease as projects mature, critical security misconfigurations often persist or reappear. We then evaluate Large Language Models (LLMs) for automated remediation under progressively enriched contextual conditions. Contextual grounding improves correction accuracy, with the best standalone model achieving 89.06%. To enhance structural correctness and schema compliance, we introduce Kubecurity, a schema-guided validation framework based on official Kubernetes specifications. Combining contextual LLM reasoning with deterministic schema enforcement achieves 98.50% correction accuracy while substantially reducing newly introduced misconfigurations. This work advances the understanding of Kubernetes security misconfigurations and demonstrates a hybrid approach to more reliable automated remediation.
Problem

Research questions and friction points this paper is trying to address.

Kubernetes
security misconfigurations
system reliability
Innovation

Methods, ideas, or system contributions that make the work stand out.

Large Language Models
Automated Remediation
Contextual Reasoning
Kubecurity
Schema-Enforcement
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
M
Mostafa Anouar Ghorab
Laval university
A
Ahmad Abdel Latif
University of Calgary
Mohamed Aymen Saied
Mohamed Aymen Saied
Laval University
Software Engineering