re0-kubernetes-sec-archive is a knowledge archive and reference collection for Kubernetes and container security attack and defense techniques.
The project addresses the need to consolidate and maintain up-to-date material on cloud-native security vulnerabilities and exploitation methods. It originated from a blog post on red-team and blue-team scenarios in Kubernetes environments published while the author worked at Tencent. The approach organizes content into three main categories: presentation slides from security conferences, research papers and whitepapers, and code examples and proof-of-concept scripts used in articles and talks. The material is designed to evolve continuously as Kubernetes security features and container attack techniques develop, overcoming the limitations of static blog posts that cannot be easily updated or corrected.
This archive suits security researchers, penetration testers, and DevSecOps engineers who need practical references on Kubernetes vulnerabilities and exploitation techniques. It draws from presentations delivered at major security conferences including HITB, BlackHat, and CIS, as well as cloud-native events like KubeCon and CloudNativeCon. The collection is particularly valuable for those building red-team and blue-team exercises or studying real-world attack scenarios in Kubernetes environments. The project explicitly plans to expand with experimental environment setup guides, Kubernetes security feature countermeasures, complete attack-defense case studies, and eBPF-based security topics.
The project is marked as work-in-progress and maintains an active focus on accumulating corrections and refining content quality. The repository structure separates slides, papers, and code artifacts to support different learning and reference needs. Development activity centers on consolidating the author's knowledge across multiple conference presentations and prior publications into a cohesive, maintainable knowledge base rather than dispersed blog posts and presentation materials.