How To Break Multi-Tenancy Again and Again ...and What We Can Learn F... Lorin Lehawany & Sven Nobis
About this talk
This talk explores the complexities of namespace-based multi-tenancy in Kubernetes and challenges the prevailing view that control-plane isolation is always superior. Speakers Lorin Lehawany and Sven Nobis delve into the hidden multi-tenancy issues that arise from workloads like machine learning and scripting capabilities, raising concerns about their secure isolation in clustered environments. The discussion highlights real-world exploits encountered in Kubeflow, Istio, and Traefik, demonstrating how these vulnerabilities can breach threat boundaries between namespaces and workloads. The session also offers a methodology for evaluating environments with isolation challenges and provides guidance on addressing these security concerns effectively.
More from this event
See all 436 talks →
Best of KubeCon + CloudNativeCon Amsterdam 2026
2:17
The Quiet Work of Forever: Sustaining Open Source Communities - O. Hope Amaechi-Okorie, JSON Schema
26:24
Evolving KServe: The Unified Model Inference Platform for Both Predictive and... F. Spolti & J. Lee
32:40
Preventing S3 Cost Storms: Applying Cortex’s Efficiency Lessons to I/O-Heav... A. Fishman-Lichterman
5:32