Exposed components

A cluster runs many services, and several are dangerous when reachable without authentication. Some are control-plane (the API server, etcd), some are node-local (the kubelet, cAdvisor), and some are add-ons (the dashboard, Tiller). Each can be a direct path to secrets, code execution, or full cluster control.

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more