Skip to content

Lesson 03 — Cluster Enumeration

Once reconnaissance has identified a Kubernetes environment, the next step is cluster enumeration.

Enumeration is the process of collecting detailed technical information about the Kubernetes cluster to understand its configuration, identify potential attack paths, and uncover security weaknesses.

Professional Cloud Penetration Testers spend significant time enumerating Kubernetes environments before attempting exploitation. A thorough enumeration phase helps identify misconfigurations, excessive privileges, exposed services, and other weaknesses while minimizing unnecessary risk.

In this lesson, you will learn how to systematically enumerate a Kubernetes cluster using the GoHackersCloud Enterprise Kubernetes Assessment Methodology.


After completing this lesson, you will be able to:

  • Understand the purpose of cluster enumeration.
  • Identify Kubernetes cluster components.
  • Enumerate nodes and workloads.
  • Review namespaces and resources.
  • Identify RBAC objects.
  • Assess networking resources.
  • Review storage resources.
  • Build a complete Kubernetes asset inventory.

CloudNova Technologies has completed the reconnaissance phase of a customer’s Kubernetes environment.

The next objective is to perform a detailed inventory of the cluster before beginning security testing.

Your team must identify every significant resource, understand how workloads communicate, determine which identities have privileged access, and document the overall cluster configuration.

This information will guide the remaining phases of the penetration test.


Cluster enumeration is the systematic process of identifying and documenting all resources within a Kubernetes cluster.

Unlike reconnaissance, which focuses on discovering the environment, enumeration gathers detailed technical information about each component.

The goal is to understand:

  • What resources exist?
  • How are they configured?
  • Who has access?
  • Which workloads are business critical?
  • Where are the potential attack paths?

Cluster Information
Nodes
Namespaces
Pods
Deployments
Services
RBAC
Secrets
Storage
Networking
Security Controls
Assessment Planning

Begin by reviewing basic cluster information.

Document:

  • Kubernetes Version
  • Cluster Name
  • Cloud Provider
  • Distribution (EKS, AKS, GKE, On-Premises)
  • API Server Version
  • Cluster Features
  • Enabled Add-ons

Version information helps identify unsupported or outdated Kubernetes releases and guides compatibility with security controls and best practices.


Review every worker and control plane node.

Document:

  • Node Name
  • Operating System
  • Kubernetes Version
  • Labels
  • Taints
  • Internal IP Address
  • External IP Address
  • Instance Type
  • Node Status
  • Ready nodes
  • Scheduling configuration
  • Resource capacity
  • Runtime configuration

Namespaces separate workloads and resources.

Review:

  • kube-system
  • kube-public
  • default
  • Development
  • Testing
  • Production
  • Monitoring
  • Security

Document:

  • Namespace owner
  • Purpose
  • Critical workloads
  • Administrative resources

Pods represent running workloads.

Review:

  • Pod Names
  • Images
  • Namespaces
  • Labels
  • Service Accounts
  • Restart Counts
  • Running Status
  • Privileged Pods

Identify:

  • Administrative workloads
  • Internet-facing applications
  • Sensitive workloads

Review:

  • Deployments
  • ReplicaSets
  • StatefulSets
  • DaemonSets
  • Jobs
  • CronJobs

Document:

  • Application purpose
  • Replica count
  • Container images
  • Namespace
  • Resource limits

Review every Kubernetes Service.

Identify:

  • ClusterIP
  • NodePort
  • LoadBalancer
  • ExternalName
  • Headless Services

Document:

  • Service exposure
  • Internal communication
  • Public endpoints

Review all authorization objects.

Assess:

  • Roles
  • ClusterRoles
  • RoleBindings
  • ClusterRoleBindings
  • Service Accounts

Identify:

  • Cluster Administrators
  • Privileged identities
  • Excessive permissions
  • Role inheritance

Review Kubernetes Secrets.

Document:

  • Secret Types
  • Mounted Secrets
  • TLS Certificates
  • Docker Registry Credentials
  • Service Account Tokens

Determine:

  • Sensitive workloads
  • Secret ownership
  • Secret usage

Review persistent storage resources.

Assess:

  • Persistent Volumes (PV)
  • Persistent Volume Claims (PVC)
  • Storage Classes
  • CSI Drivers
  • Shared Storage

Document:

  • Storage type
  • Namespace
  • Encryption
  • Access mode

Review networking resources.

Assess:

  • Network Policies
  • Ingress Controllers
  • Services
  • DNS
  • Pod Networking
  • CNI Plugin
  • Egress Controls

Determine:

  • Network segmentation
  • Internet exposure
  • Communication paths

Review existing security controls.

Assess:

  • Pod Security Admission
  • Admission Controllers
  • OPA Gatekeeper
  • Kyverno Policies
  • Runtime Security
  • Audit Logging
  • Image Scanning
  • Policy Enforcement

Document implemented controls and identify any missing protections.


During enumeration, prioritize:

  • Kubernetes API Server
  • etcd
  • Control Plane
  • Privileged Pods
  • Cluster Administrators
  • Secrets
  • CI/CD Pipelines
  • Monitoring Systems
  • Production Applications
  • Service Accounts

These assets typically require the greatest level of protection.


Enterprise Kubernetes assessments commonly identify:

  • Excessive RBAC permissions
  • Privileged workloads
  • Public LoadBalancer services
  • Missing Network Policies
  • Unencrypted Secrets
  • Outdated Kubernetes versions
  • Dormant namespaces
  • Over-permissioned Service Accounts
  • Unused storage resources
  • Misconfigured admission controls

Professional consultants should:

  • Build a complete inventory before testing.
  • Document all resources and relationships.
  • Identify business-critical workloads.
  • Validate ownership for privileged resources.
  • Record evidence throughout the assessment.
  • Prioritize high-value assets for further review.
  • Avoid making configuration changes during enumeration.

  • Enumeration provides a detailed understanding of the Kubernetes environment.
  • Nodes, workloads, identities, networking, storage, and security controls should all be reviewed.
  • A complete asset inventory improves assessment quality.
  • Identifying high-value assets early helps prioritize testing.
  • Thorough enumeration reduces blind spots and supports more effective penetration testing.

In this lesson, you learned how to enumerate a Kubernetes cluster by reviewing nodes, namespaces, workloads, services, RBAC objects, secrets, storage, networking, and security controls.

A structured enumeration process enables Cloud Penetration Testers to identify critical assets, uncover potential attack paths, and prepare for more advanced security testing.


➡️ Lesson 04 — RBAC Exploitation

In the next lesson, you will learn how attackers abuse Kubernetes Role-Based Access Control (RBAC) misconfigurations to gain unauthorized access, escalate privileges, and move laterally within Kubernetes clusters, as well as how security consultants identify and mitigate these risks during enterprise assessments.