Escaping a pod to its node is the same container breakout as anywhere, delivered through a pod spec. Kubernetes decides what a pod may request (privileged, hostPath, host namespaces) through admission control, so the escape is really about obtaining or using a pod with a dangerous spec. Once on the node, the kubelet's credentials turn one node into cluster-wide reach. The breakout primitives themselves live under Container escape.
Subtopics#
- Privileged pod: a pod with a privileged security context.
- hostPath mount: a pod mounting a node path.
- Host namespaces: a pod sharing hostPID, hostNetwork, or hostIPC.
- Kubelet credential theft: taking the node identity to reach the cluster.