Skip to main content
Run any Skill in Manus
with one click

kubelet-exploit

Stars3
Forks0
UpdatedMarch 19, 2026 at 19:28

Exploit an unauthenticated Kubernetes kubelet API (port 10250) to retrieve the cluster CA private key, even on hardened clusters with distroless containers. Use when performing authorized security testing against a Kubernetes cluster that has an exposed kubelet with anonymous auth enabled and AlwaysAllow authorization. Triggers on tasks involving kubelet exploitation, Kubernetes penetration testing, read-write kubelet attacks, distroless container exploitation, or extracting secrets from Kubernetes clusters via the kubelet API. Requires network access to the kubelet port (10250). No local `etcdctl` needed — the script runs etcdctl inside the etcd container.

Installation

Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.

File Explorer
5 files
SKILL.md
readonly