Hacking Kubernetes by Richard Knowell is a hands-on guide to understanding, attacking, and defending the world’s most popular container orchestration platform.
This book takes you step-by-step through Kubernetes architecture, threat modeling, discovery techniques, exploitation paths, and post-exploitation tactics. You’ll learn how real attackers think, the tools they use, and the weaknesses they exploit—along with practical defenses to strengthen your clusters.
Inside, you’ll
The fundamentals of containerization and Kubernetes architecture
Discovery and reconnaissance methods using GitHub, Shodan, Censys, and more
Exploitation of Kubernetes components like the API server, etcd, Kubelet, and misconfigured pods
Post-exploitation techniques, lateral movement, and full cluster compromise scenarios
Key auditing and hardening kube-bench, kube-hunter, kubeaudit, kubesec.io
Written in a practical, lab-driven style, Hacking Kubernetes is designed for penetration testers, DevSecOps engineers, and security researchers who want to understand how attackers break Kubernetes—and how to stop them.