Understanding dashboard security risks
The question of the dashboard’s security often comes up when setting up a new cluster. Securing the dashboard boils down to how the dashboard is deployed, rather than if the dashboard itself is secure. Going back to the architecture of the dashboard application, there is no sense of “security” being built in. The middle tier simply passes a token to the API server.
When talking about any kind of IT security, it’s important to look at it through the lens of defense in depth. This is the idea that any system should have multiple layers of security. If one fails, there are other layers to fill the gap until the failed layers can be addressed. A single failure doesn’t give an attacker direct access.
The most often cited incident related to the dashboard’s security was the breach of Tesla in 2018 by crypto miners. Attackers were able to access pods running in Tesla’s clusters because the dashboard...