Kubernetes

Kubernetes Kubeconfig

Kubernetes client configuration may contain cluster endpoints, client certificates, bearer tokens, or references to authentication material.

Metadata

  • id: kubernetes.kubeconfig
  • category: kubernetes
  • sensitivity: critical
  • artifact types: configuration, credential
  • tags: kubernetes, kubeconfig

Path Matchers

PathKindPlatforms
%USERPROFILE%\.kube\configfilewindows
$HOME/.kube/configfilelinux, macos
/etc/kubernetes/admin.conffilelinux
/etc/kubernetes/kubelet.conffilelinux
/etc/kubernetes/controller-manager.conffilelinux
/etc/kubernetes/scheduler.conffilelinux

Content Indicators

Literal strings:

  • apiVersion:
  • clusters:
  • contexts:

Credential Types

  • bearer-token
  • certificate
  • private-key

Impact

  • credential_access
  • remote_access

References

On this page