Case 2546E0 · Cloud · L4 Advanced
Container Escape
Practise as: Explain it · Deep dive
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Containers share the host kernel; isolation relies on namespaces, cgroups, capabilities and seccomp
- Common breakouts come from misconfiguration: privileged: true, hostPath mounts, or a mounted docker.sock
- Kernel vulnerabilities can break out of even well-configured containers because the kernel is shared
- Harden: non-root users, drop capabilities, read-only root FS, seccomp/AppArmor, Pod Security Admission restricted
- For untrusted workloads use stronger isolation such as gVisor, Kata Containers or microVMs
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.