A while ago, I lectured a multi-part series (with labs) on a simplistic hardening of a typical Kubernete’s stack. This stack would go a long way towards a compliant, hardened application service. May the notes and repository content assist your sanity checking or architectural design.
https://k8s.haxx.ninja/