Kubernetes: Master Post

I have a few Kubernetes posts queued up and will make this the master post to index and give references for the topic. If i’m missing blog posts or useful resources ping me here or twitter.Talks you should watch if you are interested in Kubernetes:https://www.youtube.com/watch?v=vTgQLzeBfRUhttps://github.com/bgeesaman/https://github.com/bgeesaman/hhkbe [demos for the talk above]https://schd.ws/hosted_files/kccncna17/d8/Hacking%20and%20Hardening%20Kubernetes%20By%20Example%20v2.pdf [side deck]https://www.youtube.com/watch?v=1k-GIDXgfLwhttps://www.youtube.com/watch?v=dxKpCO2dAy8https://www.youtube.com/watch?v=ohTq0no0ZVUBlog Posts by others:https://techbeacon.com/hackers-guide-kubernetes-securityhttps://elweb.co/the-security-footgun-in-etcd/https://www.4armed.com/blog/hacking-kubelet-on-gke/https://www.4armed.com/blog/kubeletmein-kubelet-hacking-tool/https://www.4armed.com/blog/hacking-digitalocean-kubernetes/https://github.com/freach/kubernetes-security-best-practicehttps://neuvector.com/container-security/kubernetes-security-guide/https://medium.com/@pczarkowski/the-kubernetes-api-call-is-coming-from-inside-the-cluster-f1a115bd2066https://blog.intothesymmetry.com/2018/12/persistent-xsrf-on-kubernetes-dashboard.htmlhttps://raesene.github.io/blog/2016/10/14/Kubernetes-Attack-Surface-cAdvisor/https://raesene.github.io/blog/2017/05/01/Kubernetes-Security-etcd/Auditing toolshttps://github.com/Shopify/kubeaudithttps://github.com/aquasecurity/kube-benchhttps://github.com/aquasecurity/kube-hunterCG Posts:Open Etcd: http://carnal0wnage.attackresearch.com/2019/01/kubernetes-open-etcd.htmlEtcd with kube-hunter: http://carnal0wnage.attackresearch.com/2019/01/kubernetes-kube-hunterpy-etcd.htmlcAdvisor: http://carnal0wnage.attackresearch.com/2019/01/kubernetes-cadvisor.htmlKubernetes dashboardsKublet 10255Kublet 10250     – Container Logs     – Getting shellzCloud Metadata Urls and Kubernetes-I’ll update as they get posted

Link: http://carnal0wnage.attackresearch.com/2019/01/kubernetes-master-post.html