The cluster network is flat and trusting by default, and the controls layered on top (NetworkPolicy, CNI features, a service mesh) each have gaps. Attacking this layer defeats the isolation defenders rely on to segment workloads and to protect internal services.
Subtopics#
- NetworkPolicy bypass: reaching pods a policy was meant to isolate.
- CNI and overlay abuse: spoofing and sniffing on the pod network.
- Service mesh abuse: bypassing or abusing a mesh.