cAdvisor and metrics

Telemetry endpoints are reconnaissance gold. cAdvisor (historically on 4194, and proxied by the kubelet) and metrics endpoints expose per-container detail: images, labels, command lines, and resource usage across the node or cluster. They rarely allow code execution, but they map the environment and often leak secrets in process arguments.

bash
curl -sk https://<node>:10250/metrics/cadvisor | head
curl -s http://<node>:4194/api/v1.3/subcontainers | jq '.[].spec.labels'   # legacy cAdvisor
kubectl get --raw /apis/metrics.k8s.io/v1beta1/pods                         # metrics-server

Exploitation notes#

  • Container labels and command lines frequently embed tokens, connection strings, and flags that name the next target.
  • The inventory identifies privileged and high-value pods to focus on for Kubelet API exec or token theft.
  • These endpoints are read-only; treat them as a quiet mapping step before acting.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more