A single-node Kubernetes cluster without Pod Security admission, with a foothold that may only create workloads and exec into them in one namespace. Bishop Fox's Bad Pods manifests (privileged, hostPath, hostPID, hostNetwork, hostIPC and combinations) show eight ways to turn that into node and cluster compromise.
Pas commencéVMcommit 61c96bbx86_64Secret
From the player's namespace-bound access, get root on the node and read /root/flag.txt.
Le brief de ce lab se trouve dans son dépôt.