Hands-on Lab·Kubernetes and Cloud Native Security Associate
Trust Boundaries: Authentication and Authorization
A threat model is a map of boundaries, and Kubernetes has four that matter: the human at a terminal, the Pod holding a token, the apiserver deciding twice about every request, and the node underneath. This guide crosses each one from inside a running Pod, using curl rather than kubectl so that nothing is hidden.
Kubernetes Threat Model Guide 26 of 42 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 16 min
- Reviewed25 August 2026
Written against the versions above. Anonymous requests reach the apiserver as `system:anonymous` on a default kubeadm cluster, which is why the refusal below is a 403 and not a 401. Projected ServiceAccount tokens are the default since 1.24.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA5001 | 192.168.0.41 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE01 | 192.168.0.42 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE02 | 192.168.0.43 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA5001-NODE03 | 192.168.0.44 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
-
The human identity, and what it actually is
-
The Pod identity, mounted without being asked for
-
What the token says about itself
-
Crossing into the apiserver, and being stopped at the second gate
-
The same request with no credential at all
-
The boundary that holds with no policy at all