T03 · Remote Payload Retrieval and Execution
- Location
guides/01-prerequisites.md:578- Finding
Remote Docker Installation Script Is Executed Directly by Bash
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Kubernetes deployment skill is mostly coherent documentation, but it includes under-scoped high-impact host and cluster administration steps that users should review carefully before use.
Install only if you are comfortable with an AI-assisted Kubernetes deployment guide that may lead to root SSH setup, cluster-wide RBAC changes, remote installer execution, and destructive cluster operations. Use it first in a disposable lab, require explicit approval before commands run, verify downloaded tools and images, avoid cluster-admin Dashboard tokens, protect or remove deployment SSH keys, and confirm backups and target environments before delete, drain, destroy, or reboot commands.
guides/01-prerequisites.md:578Remote Docker Installation Script Is Executed Directly by Bash
guides/01-prerequisites.md:425Downloaded kubeasz Installer Is Executed Without Integrity Verification
guides/03-production-deploy.md:496Untrusted Third-Party Container Registry Mirrors Are Recommended for Production Nodes
guides/04-post-deploy.md:907Kubernetes Dashboard Service Account Is Granted Unrestricted Cluster-Admin Access
guides/01-prerequisites.md:281Deployment Workflow Establishes Passwordless Root SSH Access with an Unencrypted Private Key
guides/04-post-deploy.md:673Kubernetes and Registry Secrets Are Passed Through Command-Line Arguments
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**症状:** SSH 登录仍需输入密码。
**解决:**
- 检查目标节点 `/root/.ssh/authorized_keys` 是否包含公钥
- 检查目标节点 SSH 配置 `PermitRootLogin yes`
- 检查目标节点 `/root/.ssh` 目录权限(700)
- 检查 `authorized_keys` 文件权限(600)
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
# 记录 CLUSTER-IP,例如:172.20.1.100
# 在集群内测试
kubectl run test-curl --rm -it --image=curlimages/curl -- curl http://<CLUSTER-IP>/
# 或使用端口转发(本地测试)
kubectl port-forward svc/nginx-svc 8080:80 &
文档指导为 Dashboard 创建 cluster-admin 级别的 ClusterRoleBinding,这赋予该账号对整个集群的完全控制权。对于面向初学者的部署指南,这种做法违反最小权限原则;一旦 Token 泄露、被截获或被误分享,攻击者即可接管整个 Kubernetes 集群。
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
配置SSH免密登录:
# 生成密钥对
ssh-keygen -t rsa -b 2048 -N '' -f ~/.ssh/id_rsa
# 批量分发公钥
for ip in <所有节点IP>; do
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
配置SSH免密登录:
# 生成密钥对
ssh-keygen -t rsa -b 2048 -N '' -f ~/.ssh/id_rsa
# 批量分发公钥
for ip in <所有节点IP>; do
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
配置SSH免密登录:
# 生成密钥对
ssh-keygen -t rsa -b 2048 -N '' -f ~/.ssh/id_rsa
# 批量分发公钥
for ip in <所有节点IP>; do
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
配置SSH免密登录:
# 生成密钥对
ssh-keygen -t rsa -b 2048 -N '' -f ~/.ssh/id_rsa
# 批量分发公钥
for ip in <所有节点IP>; do
The example PV uses hostPath, which grants pods direct access to a node filesystem path and can undermine isolation if used for general workloads. In a beginner-focused deployment guide, this is more dangerous because readers may copy it into multi-tenant or production environments where hostPath materially increases escape and tampering risk.
./ezctl destroy <cluster-name> followed by full redeployment can delete cluster state, workloads, and service availability if run on the wrong environment or without backups. In deployment troubleshooting, this is especially dangerous because operators may execute it under pressure without understanding the blast radius.
The skill explicitly states that the AI will generate or modify configuration files and execute deployment commands, but it does not require explicit user confirmation, preview of changes, or warnings about system-level impact. In a Kubernetes deployment context, these actions can alter host networking, install packages, change cluster state, and affect production infrastructure, so silently performing them is unsafe even if the overall purpose of the skill is legitimate.
The document explicitly instructs users to stop and disable host firewalls in test environments without a prominent warning about the resulting exposure. Even in a lab, this can unintentionally expose Kubernetes control-plane and node services to adjacent networks or the internet, increasing attack surface and making later compromise easier.
The documented command docker system prune -a can remove all unused images and other Docker resources, which may delete assets the user still needs and disrupt unrelated workloads on the host. Presenting it as routine cleanup without an explicit destructive-data warning raises the risk of accidental operational damage.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 记录 CLUSTER-IP,例如:172.20.1.100
# 在集群内测试
kubectl run test-curl --rm -it --image=curlimages/curl -- curl http://<CLUSTER-IP>/
# 或使用端口转发(本地测试)
kubectl port-forward svc/nginx-svc 8080:80 &
The document instructs users to destroy the cluster and reboot the node as part of troubleshooting, but it does not clearly warn that these actions are destructive and can remove workloads, configuration, and local state. In an operational context, a reader may copy-paste these commands on the wrong system or without backups, causing avoidable downtime and data loss.
The cleanup section includes full cluster destruction and node reboot steps without prominent warnings about irreversible effects, service interruption, and possible loss of locally stored application data. Because this is a quickstart guide aimed at beginners, the missing safety framing increases the chance of accidental misuse.
The guide instructs operators to set up passwordless SSH to every node and then use that trust path for automated administration, but it does not warn about key theft, root-level lateral movement, host authenticity verification, or scope minimization. In a production Kubernetes deployment context, broadly distributed SSH trust materially increases blast radius if the deployment host or private key is compromised.
The document provides commands to drain and delete worker and master nodes from the cluster. Although it says '谨慎操作' for master removal, it does not clearly warn about service interruption, pod eviction, loss of local ephemeral data, and the need to verify backups and cluster quorum before proceeding.
Manifest 描述强调为初学者提供 Kubernetes 集群部署指导,以及 AllinOne/高可用部署支持;而本节不仅是部署后验证,还系统性教授创建、更新、删除资源,节点 drain/delete,命名空间删除,以及资源配额配置等持续运维操作。这些内容属于通用集群管理与运维范畴,明显超出“部署指导”这一宣称范围。
The documentation tells users to delete a namespace and notes that it will remove all resources in it, and elsewhere includes broad deletion commands such as deleting all resources in a namespace. Because these operations can remove user workloads and data, the markdown should provide a more explicit warning about irreversibility and scope before presenting them as general-use commands.
Manifest 声明的核心目的是帮助初学者部署 Kubernetes 集群,而本节进一步指导安装 Ingress、Prometheus/Grafana、NFS Provisioner、Dashboard、Harbor 和日志系统。这些属于平台扩展与附加基础设施集成,不是完成集群部署本身所必需的验证或最小化指导,导致描述与实际内容范围不一致。
这里不仅授予了 cluster-admin 权限,而且没有明确警告其安全后果,容易让初学者把高危配置视为标准步骤。缺少风险提示会显著提高误部署概率,使高权限 Dashboard 账户长期存在并暴露在不必要的访问面前。
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 启动服务
systemctl start chronyd
systemctl enable chronyd
# 验证
chronyc sources
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 启动服务
systemctl start chronyd
systemctl enable chronyd
# 验证
chronyc sources
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 启动服务
systemctl start chronyd
systemctl enable chronyd
# 验证
chronyc sources
No suspicious patterns detected.