Lateral movement in Kubernetes is credential reuse along the cluster's own trust edges. A pod holds a service-account token that authenticates to the API server; the API exposes secrets and more tokens; the flat pod network reaches other workloads directly; and a pod's cloud workload identity reaches the surrounding cloud account. Each move takes a credential the cluster issued for a legitimate purpose and uses it to reach the next target, so movement rarely needs an exploit, only enumeration and reuse.
# the token you hold, what it reaches, and the network around you
kubectl auth can-i --list
kubectl get secrets --all-namespaces 2>/dev/null | head
kubectl get endpoints -A 2>/dev/null | head
Subtopics#
- Service account token to API: authenticating and acting with a pod token.
- Token and secret theft: harvesting credentials across namespaces.
- Pod-to-pod pivoting: reaching other workloads over the flat network.
- Cloud IAM via workload identity: following a pod identity into the cloud account.