Open cardosec

Case 2546E0 · Cloud · L4 Advanced

Container Escape

Practise as: Explain it · Deep dive
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Containers share the host kernel; isolation relies on namespaces, cgroups, capabilities and seccomp
  2. Common breakouts come from misconfiguration: privileged: true, hostPath mounts, or a mounted docker.sock
  3. Kernel vulnerabilities can break out of even well-configured containers because the kernel is shared
  4. Harden: non-root users, drop capabilities, read-only root FS, seccomp/AppArmor, Pod Security Admission restricted
  5. For untrusted workloads use stronger isolation such as gVisor, Kata Containers or microVMs

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.