Clusters deploy third-party software through charts and operators, which run with broad permissions and are trusted to create workloads and bindings. Attacking that path, a poisoned chart or an abused operator, deploys attacker intent through a trusted, privileged channel.
Subtopics#
- Helm chart abuse: malicious or over-privileged charts.
- Operator and CRD abuse: turning an operator's permissions against the cluster.