Under Docker and Kubernetes sit the low-level runtimes that actually run containers: containerd (with runc) and CRI-O. On a Kubernetes node these are the engine, and their control sockets are root-equivalent just like the Docker daemon. Reaching one from a node foothold creates privileged containers and reads everything the runtime stores, including image pull credentials.
Subtopics#
- containerd socket: the containerd control socket via ctr and nerdctl.
- CRI-O socket: the CRI runtime socket via crictl.
- crictl and ctr enumeration: inventorying containers and images.
- Image pull secret theft: recovering registry credentials from the runtime.