Kubernetes is complex, powerful… and surprisingly easy to mess up. In this talk, we’ll take a guided tour through the dark alleys of Kubernetes misconfigurations, privilege escalations, and real-world attack vectors. You’ll see live demos of how attackers exploit innocent-looking setups — and more importantly, how you can detect, prevent, and recover from them.
"Breaking Kubernetes for Fun and Profit" is a fast-paced, hands-on talk that dives into real-world security pitfalls lurking in many Kubernetes clusters. Through live demos and war stories, we’ll explore how simple misconfigurations — like overly permissive RBAC, exposed dashboards, or unscanned containers — can lead to full cluster compromise. You’ll see how attackers think, how they move laterally inside your cluster, and what tools can detect and stop them. This session isn’t just about breaking things — it’s about learning how to build safer, more resilient Kubernetes environments by thinking like a hacker.