Hands-on Lab·Kubernetes and Cloud Native Security Associate
Network-Based Attack Vectors
The pod network is flat and cluster DNS is open to everyone in it, so lateral movement needs no exploit - a name and a port are enough. This guide moves between two namespaces with curl, then closes the path with the four lines of YAML that KCSA expects you to recognise.
Kubernetes Threat Model Guide 27 of 42 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 15 min
- Reviewed25 August 2026
Written against the versions above. NetworkPolicy is enforced by the CNI. This cluster runs Cilium 1.18.1, so an ingress deny shows up as a timeout rather than a refusal - a policy on a cluster whose CNI ignores NetworkPolicy would change nothing at all.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 8 - the policy pattern, and its side effects.
- guide 23 - why a namespace is not a network boundary.
-
A victim service, and an attacker somewhere else entirely
-
DNS hands over the address, so nothing has to be scanned
-
And the flat network carries the packet
-
One NetworkPolicy, and the same request stops