A cluster runs many services, and several are dangerous when reachable without authentication. Some are control-plane (the API server, etcd), some are node-local (the kubelet, cAdvisor), and some are add-ons (the dashboard, Tiller). Each can be a direct path to secrets, code execution, or full cluster control.
Subtopics#
- Anonymous API access: the API server accepting unauthenticated requests.
- Insecure apiserver port: the legacy unauthenticated port.
- Kubelet API: the node agent's API, often able to exec in pods.
- etcd: the cluster datastore, holding every secret.
- Dashboard: the web dashboard with a privileged account.
- cAdvisor and metrics: container and node telemetry.
- API server proxy: reaching internal services through the API proxy.
- Helm Tiller: the legacy Helm v2 server with broad rights.
- Exposed kubeconfig: recovered admin credentials.