Network-Based Attack Vectors
The pod network is flat and cluster DNS is open to everyone in it, so lateral movement needs no exploit - a name and a port are enough. This guide moves between two namespaces with curl, then closes the path with the four lines of YAML that KCSA expects you to recognise.
Kubernetes Threat Model Guide 27 of 42 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1
- Built withkubeadm v1.36.3
- TimeAbout 15 min
NetworkPolicy is enforced by the CNI. This cluster runs Cilium 1.18.1, so an ingress deny shows up as a timeout rather than a refusal - a policy on a cluster whose CNI ignores NetworkPolicy would change nothing at all.
- Host kernel7.0.0-29
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
This guide includes
Use this when you have to explain why lateral movement is so cheap in a default cluster. This matters because the pod network is flat and cluster DNS answers everybody - so an attacker never has to scan for anything.
- setting up a victim service and an attacker in a namespace that should have no access
- letting DNS hand over the address, so nothing has to be scanned at all
- sending one request across the flat network, with no credential and no policy in the way
- applying one NetworkPolicy and watching the identical request stop dead
Before you start
- guide 8 - the policy pattern, and its side effects.
- guide 23 - why a namespace is not a network boundary.
-
A victim service, and an attacker somewhere else entirely
-
DNS hands over the address, so nothing has to be scanned
-
And the flat network carries the packet
-
One NetworkPolicy, and the same request stops