Cloud Native
Security Talks
RSS

KubeCon Europe 2022

Trampoline Pods: Node to Admin PrivEsc Built Into Popular K8s Platforms

Yuval Avrahami & Shaul Ben Hai, Palo Alto Networks

Abstract

Security teams work to prevent the next container escape while attackers do the opposite. Inevitably, we sometimes lose this battle, but we can still win the fight! It’s all about containing the next container escape - making sure a rogue node cannot take over the entire cluster. K8s has done a great job at de-privileging the node agent, the Kubelet, but nodes also host other credentials - their pods’ service account tokens. Following an escape, the attacker can easily harvest and abuse tokens of neighboring pods.In this talk, Yuval and Shaul will introduce the concept of Trampoline Pods - pods so powerful that if their node goes rogue, it could launch devastating attacks against the cluster and in some cases completely take over it. Covering managed K8s services and common cluster add-ons, they’ll reveal the trampoline pods installed by popular K8s platforms. They’ll also demo exploits, discuss mitigations, and release rbac-police: a tool that detects trampoline pods and K8s privEscs.Click here to view captioning/translation in the MeetingPlay platform!

More from KubeCon Europe 2022

Open in the index →
  1. Lightning Talk: Secure Multi User HPC Jobs in Kubernetes with KyvernoTrey Dockendorf, Ohio Supercomputer Center 2022-05-17
  2. The Hitchhiker's Guide to Pod SecurityLachlan Evenson, Microsoft 2022-05-18
  3. Securing Kubernetes Applications by Crafting Custom Seccomp ProfilesSascha Grunert, Red Hat 2022-05-18
  4. K8s and Active Directory Can Be Friends! How to Use Dex to Bridge the GapOnkar Bhat, Kasten by Veeam 2022-05-18
  5. How Attackers Use Exposed Prometheus Server to Exploit Kubernetes ClustersDavid de Torres Huerta & Miguel Hernández, Sysdig 2022-05-18
  6. Bypassing Falco: How to Compromise a Cluster without Tripping the SOCShay Berkovich, BlackBerry 2022-05-18
  7. Threat Modelling Kubernetes: A Lightspeed IntroductionLewis Denham-Parry, Control Plane 2022-05-19
  8. Securing Your Container Native Supply Chain with SLSA, Github and TektonLaurent Simon, Google & Priya Wadhwa, Chainguard 2022-05-19
  9. Make the Secure Kubernetes Supply Chain Work for YouAdolfo García Veytia, Chainguard 2022-05-19
  10. Fun with Continuous ComplianceAnn Wallace, Shopify & Zeal Somani, Google 2022-05-19
  11. Distributing Supply Chain Artifacts with OCI & ORAS ArtifactsSteve Lasker, Microsoft 2022-05-19
  12. Too Much to Choose – Making Sense of a Smorgasbord of Security StandardsAnais Urlichs & Rory McCune, Aqua Security 2022-05-20
  13. Throw Away Your Passwords: Trusting Workload IdentityRic Featherstone, ControlPlane 2022-05-20
  14. Three Surprising K8s Networking “Features” and How to Defend Against ThemJames Cleverley-Prance, ControlPlane 2022-05-20
  15. Multi-Cloud Workload Identity With SPIFFEJake Sanders & Charlie Egan, Jetstack 2022-05-20
  16. Full Mesh Encryption in Kubernetes with WireGuard and CalicoPeter Kelly, Tigera 2022-05-20
  17. Attacking & Defending Kubernetes TEE Enclaves in Critical InfrastructureRobert Ficcaglia, SunStone Secure, LLC 2022-05-20