Skip to content

Latest commit

History

12 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

Devslop_K8_ctf_logo

This workshop/CTF is part of the OWASP DevSlop project was hosted at the 2021 Diana Initiative CTF. It is intended to be beginner-friendly CTF on a lightweight, low-cost Kubernetes setup, that you can run in your own AWS account. Its format is a little different than normal CTF's. The goal is to introduce you gently to Kubernetes concepts (learning exercises) and then to break the security of something (breaker exercises) and finally to fix the thing you just broke (builder exercises). We hope that this format helps you learn the introductory concepts well enough to understand why you are able to violate security and then solve the underlying security problem.

Big shout out to the Kops team. Without Kops this would have made individualized Kubnernetes clusters near impossible to be both low cost and light weight.

Most of this CTF was built by @thedeadrobots

To get started head to the Start_Here.md page to build out your cluster.

ChallengeDescriptionType
Challenge 01K8 Overview - History of VirutalizationLearner
Challenge 02K8 Overview - Overview of Docker/ContainersLearner
Challenge 03K8 Overview - What is Orchestration?Learner
Challenge 04K8 Overview - History of KubernetesLearner
Challenge 05K8 Overview - Kubernetes ArchitectureLearner
Challenge 06K8 Overview - Kubernetes Objects & OrganizationLearner
Challenge 07K8 Setup - Logging into KubernetesBuilder
Challenge 08K8 Setup - Using kubectlBuilder
Challenge 09K8 Setup - Kubernetes AuthN/AuthZ OverviewLearner
Challenge 10K8 Setup - Kubernetes DashboardBuilder
Challenge 11K8 Networking - ClusterIPBuilder
Challenge 12K8 Networking - NodePortBuilder
Challenge 13K8 Networking - LoadBalancerBuilder
Challenge 14K8 Deployment - Simple DeploymentBuilder
Challenge 15K8 Deployment - Rolling UpdatesBuilder
Challenge 16K8 Security - Finding Creds in CodeBreaker
Challenge 17K8 Security - Using Kube SecretsBuilder
Challenge 18K8 Security - SSRF on K8Breaker
Challenge 19K8 Security - Finding SSRF bugs with SemgrepBuilder
Challenge 20K8 Security - Container Escape to HostBreaker
Challenge 21K8 Security - Intro to OpenPolicyAgentLearner
Challenge 22K8 Security - OPA to Restrict Host AccessBuilder
Challenge 23K8 Security - Namespace BypassBreaker
Challenge 24K8 Security - Prevent Namespace Bypass w/ CiliumBuilder
Challenge 25K8 Security - Consume Cluster Resources / DoSBreaker
Challenge 26K8 Security - OPA to Enforce Resource LimitsBuilder
Challenge 27K8 Security - Scanning Containers for VulnerabilitiesBreaker
Challenge 28K8 Security - OPA to Enforce Trusted Image SourcesBuilder
Challenge 29K8 Security - Using Kube-BenchBuilder

#TODO Support / Maintenance

About

A beginner-friendly Kubernetes CTF that you can deploy yourself.

Resources

Stars

12 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors