An Exposed Docker Daemon Is Root on the Host
Topic 16 of my Kubernetes journey: why an exposed Docker daemon means root on the host, the 2375 vs 2376 ports, and locking it down with TLS and client certs.
Topic 16 of my Kubernetes journey: why an exposed Docker daemon means root on the host, the 2375 vs 2376 ports, and locking it down with TLS and client certs.
Topic 32 of my Kubernetes journey: why containers share one kernel, what gVisor and Kata Containers actually change, and picking a runtime with RuntimeClass.
Topic 4 of my Kubernetes journey: the 4Cs of cloud native security explained, then a real attack chain from an open Docker port to a rigged poll database.
The complete Kubernetes security journey mapped end to end: 42 topics from RBAC to runtime, organised by the attacker's path and by defence, with the pentest notes.