Authors - Marlon Kulatunga, Kaavya Raigambandarage, Senali Guruge, Themiya Alwis, Amila Nuwan Senarathne, Kavinga Yapa Abeywardena Abstract - Contemporary Kubernetes deployments suffer from two fundamental shortcomings: admission control mechanisms apply static rule sets without accounting for namespace operational context, and content inspection services governed by RFC 3507 remain disconnected from the orchestration layer. This work presents an integrated four-module security framework that jointly addresses both deficiencies. A probabilistic namespace characterisation algorithm employing seven weighted indicators achieves 96.7% accuracy in determining deployment tiers, even when metadata labels are absent or deliberately misleading. A compliance-driven policy orchestrator aligned with CIS Kubernetes Benchmark controls and PCI-DSS v4.0 requirements translates a unified constraint representation into artefacts for both OPA Gatekeeper and Kyverno, attaining 99.2% cross-engine decision parity. An environment-responsive traffic manager generates tier-specific Istio routing configurations, while a custom Kubernetes operator governs content scanning pod lifecycles through a multi-dimensional wellness metric that captures security-relevant signals invisible to conventional autoscalers. Evaluation on a five-node K3s cluster demonstrates full compliance coverage across 93 benchmark controls and 28 regulatory mandates, sub-five-second failover under all disruption scenarios, and correct detection of degraded scanning capability that CPU and memory metrics alone would overlook.