Your question is Secure Kubernetes Pipeline Access. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
You're working on platform pipelines that run on Kubernetes, and you want to lock down both cluster API access and the container runtime layer before expanding usage.
What security best practices do you implement to harden Kubernetes API access and container runtimes?