Persistence in Kubernetes hides in the cluster's own mechanisms: controllers that keep workloads running, cronjobs that fire on a schedule, static pods the API never sees, RBAC objects that quietly restore access, and admission webhooks that touch every new object. The best footholds look like ordinary cluster configuration.
Subtopics#
- Malicious workloads: deployments and daemonsets that self-heal.
- CronJobs: scheduled attacker execution.
- Static pods: node-level pods outside the API.
- RBAC backdoor: hidden roles, bindings, and accounts.
- Admission webhooks: intercepting cluster operations.
- Mutating webhook backdoor: injecting into every new workload.