What's inside
A practical architecture guide for running PCI DSS 4.0.1 compliant workloads on Kubermatic Kubernetes Platform: covering CDE scoping, network segmentation, secrets management, and control mapping across all 12 requirements. Includes a KKP-specific requirements checklist, third-party tool recommendations, and a glossary for compliance and platform teams working together.
01. CDE scoping & architecture
How to define and isolate the cardholder data environment boundary on KKP.
02. Network segmentation
Isolating in-scope workloads with dedicated node pools and default-deny network policies.
03. Secrets & data protection
Encryption, secrets management, and audit logging controls for in-scope clusters.
04. Control mapping, all 12 requirements
How KKP maps to every PCI DSS 4.0.1 requirement, requirement by requirement.
05. KKP requirements checklist
A step-by-step checklist platform and compliance teams can work through together.
06. Recommended third-party tools
Vetted options for scanning, monitoring, and policy enforcement in the CDE.
07. Glossary
Shared terminology so compliance and platform teams are speaking the same language.
