Pod escape to node

Escaping a pod to its node is the same container breakout as anywhere, delivered through a pod spec. Kubernetes decides what a pod may request (privileged, hostPath, host namespaces) through admission control, so the escape is really about obtaining or using a pod with a dangerous spec. Once on the node, the kubelet's credentials turn one node into cluster-wide reach. The breakout primitives themselves live under Container escape.

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more