Definition. The sum of measures that reduce the attack surface and exploit tolerance of a Linux kernel: enabling protection mechanisms (KASLR, SMEP/SMAP, BTI, stack protector), restricting subsystems (kernel.unprivileged_userns_clone, kernel.kptr_restrict), mitigations for CPU vulnerabilities and LSMs such as SELinux or AppArmor.
Why it matters. Even if a kernel patch has not been rolled out yet, a hardened kernel can slow down or prevent many exploits. Hardening is not a one-off step but part of running worker nodes.
Related. Kernel LPE, Container Escape, Pod Security Standards, Runtime Security