Most Kubernetes attacks start from a single compromised pod and climb. A pod carries an identity (a service-account token), sits on a flat network, and runs on a node that holds credentials for the whole cluster. The path is familiar: enumerate, reach exposed components, escalate through RBAC, escape to the node, move laterally, and persist. Escaping the pod to its node uses the runtime-agnostic primitives in Container escape; this area is the cluster-level attack model around them.
Subtopics#
- Cluster enumeration: mapping the cluster and your identity from a pod.
- Exposed components: unauthenticated or reachable control-plane and node components.
- RBAC privilege escalation: turning limited permissions into more.
- Pod escape to node: breaking out of a pod to its node.
- Lateral movement: moving between workloads, namespaces, and into the cloud.
- Persistence: keeping access across restarts and remediation.
- Network: attacking the cluster network and service mesh.
- Supply chain: Helm, operators, and admission as deployment paths.