Posts on k8s-security
5 posts on k8s-security. Notes from public sources and my own test lab.
The Orchestrator or an Insider Trojan? Invisible Dangers in the Kubernetes World
Security has shifted from physical firewalls to the orchestration layer. Let's dive into the dark corners of Kubernetes security—from API Server leaks to RBAC misconfigurations—and talk about how to keep the cluster safe.
Handing Over Your K8s Cluster on a Silver Platter: Config Errors and Cold Hard Truths
Ever wondered how a single YAML line can turn your infrastructure into a public playground? Let's dive into common Kubernetes misconfigurations from a Red Team perspective and look at how to actually secure them.
Getting Lost in YAML: The High Cost of Leaving Kubernetes Security to 'Default' Settings
Think your K8s cluster is secure because it's 'running'? Think again. From RBAC nightmares to privileged pod escapes, let's look at why default settings are a Red Teamer's best friend.
The Day You Exposed Kube-apiserver to the Internet, You Handed Over the Keys to Your Cluster
If you aren't seeing 401 or 403 errors in your logs, you're either not being targeted or you're already compromised. Let's dive into the dirty realities of Kubernetes security and how to harden your cluster.
Kubernetes: Orchestration Magic or a Trojan Horse Within?
Is your K8s cluster a secure fortress or just a playground for attackers? Let's dive into API server security, RBAC pitfalls, and why Base64 isn't encryption.