To pull private images, the runtime stores registry credentials on the node, and Kubernetes materializes image pull secrets there too. A node foothold recovers them from the runtime's auth files and from the kubelet's on-disk secret state, then reuses them against the registry.
# Runtime and kubelet auth material on the node
find / -name config.json -path '*containers*' 2>/dev/null -exec cat {} \;
cat /var/lib/kubelet/config.json 2>/dev/null
ls /var/lib/kubelet/pods/*/volumes/kubernetes.io~secret/*/.dockerconfigjson 2>/dev/null
Exploitation notes#
- Pull credentials often reach registries beyond the images on this node, widening access to the whole project's private images.
- Recovered credentials feed Registry access; push rights among them enable backdooring.
- Kubelet-materialized secrets on the node also include non-registry secrets mounted into pods, worth sweeping at the same time.