# Kubernetes Security

Container orchestration expands the attack surface. We test K8s clusters the way real attackers approach them — from RBAC to pod escapes.

### [A Pentester’s Approach to Kubernetes Security — Part 2](/content/blog/a-pentester-s-approach-to-kubernetes-security-part-2/index.html)

Part 2 of Appsecco's Kubernetes pentest series, focusing on overprivileged RBAC, cloud IAM to Kubernetes mappings, and how attackers escape from cluster to cloud.  
Appsecco·November 16, 2023 ·6 min

### [A Pentester’s Approach to Kubernetes Security — Part 1](/content/blog/a-pentester-s-approach-to-kubernetes-security-part-1/index.html)

A practical rundown of the most common Kubernetes misconfigurations found during real pentests, covering network policy gaps, exposed API proxies, and service account privilege issues.  
Appsecco·November 8, 2023 ·4 min

### [Hacking an AWS hosted Kubernetes backed product, and failing](/content/blog/hacking-an-aws-hosted-kubernetes-backed-product-and-failing/index.html)

A transparent pentest post-mortem: how Appsecco attacked a well-architected AWS EKS product, what attack paths were tried, and which security design decisions stopped them cold.  
Appsecco·June 2, 2022 ·8 min

### [Kubernetes From an Attacker’s Perspective — OWASP Bay Area Meetup](/content/blog/kubernetes-from-an-attacker-s-perspective-owasp-bay-area-mee/index.html)

Slides, video, and Q&A from an OWASP Bay Area webinar on attacking Kubernetes clusters, with live demonstrations on a GKE cluster covering namespace breakouts and host path exploits.  
Appsecco·June 3, 2020 ·3 min
