Slide 21
Slide 21 text
Namespace
Break-out
using
hostPath
Volume
Mount
• I am a developer and have access to
CRUD Pod in developers
namespace
• I am an attacker and just gained
access to a Pod with CI/CD engine
that needs to create more Pods to
run build jobs
Assume any one of the
following
• We can create Pod, but we are
hopefully, greatly restricted to a
single namespace
Bottom line