Rory McCune

Kubernetes Multi-Tenant Blues

Date
Recording
None listed

One of the attractions of Kubernetes is being able to save money on cloud bills, and what better way to save money that running everything in one massive cluster with all our different teams (or customers) deploying their applications in one place! Unfortunately once we’ve got our cluster set-up we might end up singing the multi-tenant blues as it can be a bit tricky to isolate our workloads properly.

We’re going to talk about the different layers that make up a Kubernetes cluster and how the stack of different projects and re-use of older Linux primitives makes good multi-tenant security hard to achieve. We’ll also look at some of the risks of breakout from containers down to shared cluster nodes, how the Kubernetes authorization system has edge cases that can allow for privilege escalation and why the networking model implemented by Kubernetes does not lend itself to scenarios where hostile tenants are present, especially as Kubernetes is SSRF as a service!

We’ll also look at a high-level at how these problems can be solved and the trade-offs of different approaches to improving multi-tenant Kubernetes cluster security, so that attendees can make informed decisions on where they want to place the security boundaries in their Kubernetes environments.

This talk was delivered at 44CON 2026.