
Presentation of the course and chapters
Learn the Kubernetes control plane components—API server, etcd, scheduler, and controller manager—and pods, services, and deployment methods like pod deployment, replica set, stateful set, jobs, cron jobs, and replication controller.
Deploy a pod on a minikube Kubernetes cluster using the alpine image and kubectl apply, then inspect the pod and its service account details with kubectl get pod -o wide.
Explore Kubernetes networking fundamentals, CNI plugins, and pod-to-pod communication across nodes, with Calico, Cilium, and OVN for Kubernetes managing IPs and policies.
Explore Kubernetes security fundamentals, mastering RBAC with role, role binding, and cluster roles, while securing secrets, pod security admission modes, and security context settings.
Define your pentest scope for Kubernetes by mapping external and internal threat actors, simulating misconfigurations, secrets leakage, and lateral movement to elevate privileges to cluster admin.
Learn practical pen testing in Kubernetes through information gathering and enumeration with open-source tools. Discover misconfigurations and perform a privilege escalation demo to gain cluster admin access.
Privileged pod mounts the node filesystem to access the admin service account token from another namespace. The demo uses that token to gain kube-system admin privileges.
This comprehensive course bridges the gap between Kubernetes fundamentals and security testing, designed for security enthusiasts and penetration testers who want to expand their skillset into cloud-native environments. You'll learn how to identify, assess, and exploit security vulnerabilities in Kubernetes clusters through hands-on exercises and practical scenarios.
The course begins with essential Kubernetes concepts, including pods, services, deployments, and networking, providing you with the foundational knowledge needed to understand the attack surface. You'll learn how to set up your own testing environment using tools like Minikube or Kind, ensuring you can practice safely and independently.
As you progress, you'll discover common misconfigurations and security weaknesses in Kubernetes deployments, such as:
Exposed Kubernetes dashboards and API servers
Misconfigured RBAC permissions
Container escape techniques
Secrets management vulnerabilities
Network policy gaps
The course emphasizes practical skills with guided laboratories where you'll learn to:
Use security assessment tools specific to Kubernetes environments
Perform reconnaissance on cluster components
Exploit service account tokens and credentials
Escalate privileges within the cluster
Move laterally between namespaces and pods
Identify and exploit vulnerable workloads
Special attention is given to defensive considerations, helping you understand how to document findings and provide actionable remediation advice. By the end of the course, you'll have the skills to independently conduct security assessments of Kubernetes clusters and provide valuable insights for hardening these environments.
Prerequisites include basic familiarity with Linux commands and container concepts. All necessary tools and techniques will be thoroughly explained, making this course accessible to security practitioners beginning their journey into container orchestration security.