Kubernetes 生产环境中的错误配置:分类、演化及基于大语言模型的自动修复
Kubernetes Misconfigurations in the Wild: Taxonomy, Evolution, and Automated Repair with Large Language Models
浏览论文内容
中文总结 AI 辅助
基于 2,662 个 Stack Overflow 问题,研究 Kubernetes 安全错误配置的分类与演化,并提出结合上下文 LLM 与模式验证的 Kubecurity 框架,将修复准确率提升至 98.50%。
中文摘要 AI 辅助
Kubernetes 被广泛用于编排云原生应用,但其声明式配置模型常常引入威胁系统可靠性的安全错误配置。尽管已有可用的检测工具,错误配置模式及可扩展的修复方法仍未被充分理解。本文基于 2,662 个开发者报告的 Stack Overflow 问题,对 Kubernetes 安全错误配置进行了实证研究。我们推导出跨配置对象和类别的常见安全弱点分类体系。我们分析了严重性变化,并调查了错误配置在孵化器与稳定项目阶段之间如何演化。研究结果显示,随着项目成熟,某些操作性问题有所减少,但关键的安全错误配置往往持续存在或重新出现。随后,我们在逐步丰富的上下文条件下评估了大语言模型(LLMs)在自动修复中的表现。上下文基础增强提升了修正准确率,最佳独立模型达到 89.06%。为提高结构正确性和模式合规性,我们引入了 Kubecurity,一个基于官方 Kubernetes 规范的模式引导验证框架。将上下文 LLM 推理与确定性模式执行相结合,修正准确率达到 98.50%,同时大幅减少了新引入的错误配置。本工作推进了对 Kubernetes 安全错误配置的理解,并展示了一种更可靠的混合自动修复方法。
英文摘要
Kubernetes is widely used to orchestrate cloud-native applications, yet its declarative configuration model often introduces security misconfigurations that threaten system reliability. Despite available detection tools, misconfiguration patterns and scalable remediation remain insufficiently understood. This paper presents an empirical study of Kubernetes security misconfigurations based on 2,662 developer-reported Stack Overflow issues. We derive a taxonomy of recurring security weaknesses across configuration objects and categories. We analyze severity variations and investigate how misconfigurations evolve between incubator and stable project stages. Findings show that while some operational issues decrease as projects mature, critical security misconfigurations often persist or reappear. We then evaluate Large Language Models (LLMs) for automated remediation under progressively enriched contextual conditions. Contextual grounding improves correction accuracy, with the best standalone model achieving 89.06%. To enhance structural correctness and schema compliance, we introduce Kubecurity, a schema-guided validation framework based on official Kubernetes specifications. Combining contextual LLM reasoning with deterministic schema enforcement achieves 98.50% correction accuracy while substantially reducing newly introduced misconfigurations. This work advances the understanding of Kubernetes security misconfigurations and demonstrates a hybrid approach to more reliable automated remediation.
发表机构
- Laval university(拉瓦尔大学)
- University of Calgary(卡尔加里大学)
机构由 AI 辅助整理,请以论文原文为准。