Compromised API Server
Exploiting Kubernetes API server vulnerabilities and how attackers gain unauthorized access.
Exploiting Kubernetes API server vulnerabilities and how attackers gain unauthorized access.
How to use manifest-based admission control in Kubernetes v1.36 to close bootstrap and self-protection gaps in admission policies and webhooks.
How to migrate away from the deprecated Service .spec.externalIPs field in Kubernetes 1.36 and block its reuse with the DenyServiceExternalIPs admission controller.
How to enforce security defaults using MutatingAdmissionPolicy, the CEL-based in-process alternative to mutating admission webhooks, GA in Kubernetes v1.36.
How to restrict anonymous access to the Kubernetes API server to specific endpoints using AuthenticationConfiguration, stable since Kubernetes 1.34.
Best practices for protecting the Kubernetes API server against unauthorized access and exploitation.