4 ms·
Something to be aware of (and a general comment about k8s in general) is that k8s is not suitable for use in hostile multi-tenant scenarios like the one that yo
by localhost 7y ago
Something to be aware of (and a general comment about k8s in general) is that k8s is not suitable for use in hostile multi-tenant scenarios like the one that you're describing. Once an attacker escapes from the container (see HN archives for lots of examples of this), they can p0wn the entire cluster. Jessie Frazelle has a great post on this: https://blog.jessfraz.com/post/hard-multi-tenancy-in-kubernetes/ https://blog.jessfraz.com/post/hard-multi-tenancy-in-kuberne...
There are expensive ways to deal with this today, e.g., running each user isolated in a separate VM. Hopefully we will have better solutions in the near future.
- airocker 7y agoWe were starting to work on disabling kubernetes cluster access. We will try the steps in the post.