Cluster Grey Zone: Risks in Managed Cluster Middleware
May 01, 2023
30 min
Free
kubernetes
cloud-security
managed-kubernetes
eks
gke
aks
cluster-middleware
attack-surface
privilege-escalation
container-security
threat-modeling
fluent-bit
node-problem-detector
Description
This talk investigates the 'grey zone' of managed cluster middleware in Kubernetes environments. While users are aware of their own workloads, automatically deployed components by cloud providers (like EKS, AKS, GKE) running on worker nodes introduce an often-overlooked threat surface. The speakers analyze the security posture of this Managed Cluster Middleware (MCM), demonstrating how attackers can exploit misconfigurations in components like Node Problem Detector and Fluent Bit to gain elevated privileges and exfiltrate sensitive data. They highlight the challenges in securing these components due to shared responsibility models and the limitations of traditional security tools.