Auditing Namespace As Tenant Boundary

Audit a Kubernetes namespace that is treated as a tenant isolation boundary for the isolation it does not actually provide: cluster-scoped resources and nodes shared across namespaces, RBAC that grants a tenant reach beyond its own namespace, missing network policy so pods cross namespaces freely, and shared cluster services (DNS, ingress, admission, storage classes) that see or serve every tenant. Covers multi-tenant clusters where each tenant is given a namespace and the namespace is assumed to contain them. Use when a namespace is the unit of tenant separation and the assumption is that a tenant cannot affect or observe another. The tenant confined to a namespace is the source, the cross-tenant resource or namespace it reaches is the sink, and the isolation the namespace does not enforce is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/auditing-namespace-as-tenant-boundary commit a2a6c4f371

Frequently asked questions

npx skillmds@latest add unboundcompute/auditing-namespace-as-tenant-boundary