Lesson 03 — Cluster Enumeration
Welcome
Section titled “Welcome”Once reconnaissance has identified a Kubernetes environment, the next step is cluster enumeration.
Enumeration is the process of collecting detailed technical information about the Kubernetes cluster to understand its configuration, identify potential attack paths, and uncover security weaknesses.
Professional Cloud Penetration Testers spend significant time enumerating Kubernetes environments before attempting exploitation. A thorough enumeration phase helps identify misconfigurations, excessive privileges, exposed services, and other weaknesses while minimizing unnecessary risk.
In this lesson, you will learn how to systematically enumerate a Kubernetes cluster using the GoHackersCloud Enterprise Kubernetes Assessment Methodology.
Learning Objectives
Section titled “Learning Objectives”After completing this lesson, you will be able to:
- Understand the purpose of cluster enumeration.
- Identify Kubernetes cluster components.
- Enumerate nodes and workloads.
- Review namespaces and resources.
- Identify RBAC objects.
- Assess networking resources.
- Review storage resources.
- Build a complete Kubernetes asset inventory.
Business Scenario
Section titled “Business Scenario”CloudNova Technologies has completed the reconnaissance phase of a customer’s Kubernetes environment.
The next objective is to perform a detailed inventory of the cluster before beginning security testing.
Your team must identify every significant resource, understand how workloads communicate, determine which identities have privileged access, and document the overall cluster configuration.
This information will guide the remaining phases of the penetration test.
What is Cluster Enumeration?
Section titled “What is Cluster Enumeration?”Cluster enumeration is the systematic process of identifying and documenting all resources within a Kubernetes cluster.
Unlike reconnaissance, which focuses on discovering the environment, enumeration gathers detailed technical information about each component.
The goal is to understand:
- What resources exist?
- How are they configured?
- Who has access?
- Which workloads are business critical?
- Where are the potential attack paths?
Enumeration Workflow
Section titled “Enumeration Workflow”Cluster Information
↓
Nodes
↓
Namespaces
↓
Pods
↓
Deployments
↓
Services
↓
RBAC
↓
Secrets
↓
Storage
↓
Networking
↓
Security Controls
↓
Assessment PlanningCluster Information
Section titled “Cluster Information”Begin by reviewing basic cluster information.
Document:
- Kubernetes Version
- Cluster Name
- Cloud Provider
- Distribution (EKS, AKS, GKE, On-Premises)
- API Server Version
- Cluster Features
- Enabled Add-ons
Why It Matters
Section titled “Why It Matters”Version information helps identify unsupported or outdated Kubernetes releases and guides compatibility with security controls and best practices.
Node Enumeration
Section titled “Node Enumeration”Review every worker and control plane node.
Document:
- Node Name
- Operating System
- Kubernetes Version
- Labels
- Taints
- Internal IP Address
- External IP Address
- Instance Type
- Node Status
Review
Section titled “Review”- Ready nodes
- Scheduling configuration
- Resource capacity
- Runtime configuration
Namespace Enumeration
Section titled “Namespace Enumeration”Namespaces separate workloads and resources.
Review:
- kube-system
- kube-public
- default
- Development
- Testing
- Production
- Monitoring
- Security
Document:
- Namespace owner
- Purpose
- Critical workloads
- Administrative resources
Pod Enumeration
Section titled “Pod Enumeration”Pods represent running workloads.
Review:
- Pod Names
- Images
- Namespaces
- Labels
- Service Accounts
- Restart Counts
- Running Status
- Privileged Pods
Identify:
- Administrative workloads
- Internet-facing applications
- Sensitive workloads
Deployment Enumeration
Section titled “Deployment Enumeration”Review:
- Deployments
- ReplicaSets
- StatefulSets
- DaemonSets
- Jobs
- CronJobs
Document:
- Application purpose
- Replica count
- Container images
- Namespace
- Resource limits
Service Enumeration
Section titled “Service Enumeration”Review every Kubernetes Service.
Identify:
- ClusterIP
- NodePort
- LoadBalancer
- ExternalName
- Headless Services
Document:
- Service exposure
- Internal communication
- Public endpoints
RBAC Enumeration
Section titled “RBAC Enumeration”Review all authorization objects.
Assess:
- Roles
- ClusterRoles
- RoleBindings
- ClusterRoleBindings
- Service Accounts
Identify:
- Cluster Administrators
- Privileged identities
- Excessive permissions
- Role inheritance
Secret Enumeration
Section titled “Secret Enumeration”Review Kubernetes Secrets.
Document:
- Secret Types
- Mounted Secrets
- TLS Certificates
- Docker Registry Credentials
- Service Account Tokens
Determine:
- Sensitive workloads
- Secret ownership
- Secret usage
Storage Enumeration
Section titled “Storage Enumeration”Review persistent storage resources.
Assess:
- Persistent Volumes (PV)
- Persistent Volume Claims (PVC)
- Storage Classes
- CSI Drivers
- Shared Storage
Document:
- Storage type
- Namespace
- Encryption
- Access mode
Network Enumeration
Section titled “Network Enumeration”Review networking resources.
Assess:
- Network Policies
- Ingress Controllers
- Services
- DNS
- Pod Networking
- CNI Plugin
- Egress Controls
Determine:
- Network segmentation
- Internet exposure
- Communication paths
Security Control Enumeration
Section titled “Security Control Enumeration”Review existing security controls.
Assess:
- Pod Security Admission
- Admission Controllers
- OPA Gatekeeper
- Kyverno Policies
- Runtime Security
- Audit Logging
- Image Scanning
- Policy Enforcement
Document implemented controls and identify any missing protections.
High-Value Assets
Section titled “High-Value Assets”During enumeration, prioritize:
- Kubernetes API Server
- etcd
- Control Plane
- Privileged Pods
- Cluster Administrators
- Secrets
- CI/CD Pipelines
- Monitoring Systems
- Production Applications
- Service Accounts
These assets typically require the greatest level of protection.
Common Enumeration Findings
Section titled “Common Enumeration Findings”Enterprise Kubernetes assessments commonly identify:
- Excessive RBAC permissions
- Privileged workloads
- Public LoadBalancer services
- Missing Network Policies
- Unencrypted Secrets
- Outdated Kubernetes versions
- Dormant namespaces
- Over-permissioned Service Accounts
- Unused storage resources
- Misconfigured admission controls
Consultant Best Practices
Section titled “Consultant Best Practices”Professional consultants should:
- Build a complete inventory before testing.
- Document all resources and relationships.
- Identify business-critical workloads.
- Validate ownership for privileged resources.
- Record evidence throughout the assessment.
- Prioritize high-value assets for further review.
- Avoid making configuration changes during enumeration.
Key Takeaways
Section titled “Key Takeaways”- Enumeration provides a detailed understanding of the Kubernetes environment.
- Nodes, workloads, identities, networking, storage, and security controls should all be reviewed.
- A complete asset inventory improves assessment quality.
- Identifying high-value assets early helps prioritize testing.
- Thorough enumeration reduces blind spots and supports more effective penetration testing.
Lesson Summary
Section titled “Lesson Summary”In this lesson, you learned how to enumerate a Kubernetes cluster by reviewing nodes, namespaces, workloads, services, RBAC objects, secrets, storage, networking, and security controls.
A structured enumeration process enables Cloud Penetration Testers to identify critical assets, uncover potential attack paths, and prepare for more advanced security testing.
What’s Next?
Section titled “What’s Next?”➡️ Lesson 04 — RBAC Exploitation
In the next lesson, you will learn how attackers abuse Kubernetes Role-Based Access Control (RBAC) misconfigurations to gain unauthorized access, escalate privileges, and move laterally within Kubernetes clusters, as well as how security consultants identify and mitigate these risks during enterprise assessments.