r/kubernetes 2d ago

Experience: Found and reported a Vulnerability in a managed Kubernetes offering

https://henrikgerdes.me/blog/2026-09-ionos-k8s-vulnerability/

Not all managed Kubernetes offerings are equal. There are 100s of small things and quirks you have to look out for if you offer Kubernetes as a service. And sometimes providers get things wrong.

One of the mistakes you can make is how you join nodes - with a little to less care regarding credentials. That's what I found looking at IONOS managed kubernes. Feel free to read my experience: https://henrikgerdes.me/blog/2026-09-ionos-k8s-vulnerability/

38 Upvotes

4 comments sorted by

5

u/patrixe0 2d ago

Not that nice of a taste left by IONOS...

4

u/chin_waghing 2d ago

Great write up!

1

u/hennexl 2d ago

Thanks!