Kubernetes Threat Vectors - Security Measures Report

For most Kubernetes deployments, there are three major categories of threat vectors. It's important to understand where these fall within your threat model, since thinking about who might attack your system, and how they would do it, will help prioritize your security efforts.

The information presented in this document is for technical audiences who are interested in prioritizing their Kubernetes security efforts to protect against three major categories of threat vectors:

  1. Preventing external attackers from gaining access and elevating privileges
  2. Containing attacks on compromised containers
  3. Placing restrictions on what users can do to block the malicious user

Considering these threats, this document examines the possible lines of defense from a security perspective and technical security measures are offered.

