Skip to content

Add a warning about the possibility of executing remote code using kubectl config #28013

@savitharaghunathan

Description

@savitharaghunathan

This is a Feature Request

Add a warning about the possibility of remote code execution to kubectl config concepts and/or tasks page

If possible, please add more documentation to https://kubernetes.io/docs/reference/generated/kubectl/kubectl-commands#config

Background reading: https://banzaicloud.com/blog/kubeconfig-security/

Thanks, @tabbysable for bringing this issue to attention.

What would you like to be added
Warning or more documentation around possible kubectl config options

Why is this needed
This would help cluster admins to be aware of the possibility of a certain attack vector (remote code exec) using kubectl config

/assign @gracenng

Metadata

Metadata

Assignees

Labels

kind/featureCategorizes issue or PR as related to a new feature.sig/securityCategorizes an issue or PR as relevant to SIG Security.triage/acceptedIndicates an issue or PR is ready to be actively worked on.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions