Uploaded December 2025 | Updated September 2026, 3 weeks ago
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/0f/One%20Cluster%20to%20Rule%20Them%20All.pdf
As organizations scale their on-prem or cloud-native infrastructure, the attractiveness of a multi-tenant Kubernetes cluster is undeniable. The promise of reduced operational overhead, centralized management, and significant cost savings is pushing more and more teams to consolidate their workloads. But, how isolated are each of the development teams' access and workloads? What level of protection do solutions like Capsule and Kyverno provide, and where are the gaps? This talk dives deep into the unique security landscape of multi-tenant Kubernetes by analyzing the specific security needs of multi-tenant clusters and getting hands on with our newly released Kubernetes Penetration testing tool: VirtueKube. We will introduce theory and quickly move to live demonstrations and exploitation.
Nick Coblentz
Virtue Security
Application Pentester
Nick has been an application penetration tester for more than 15 years. He also volunteers his time to help moderate PortSwigger's discord server. nick.coblentz@gmail.com
linkedin.com/in/ncoblentz
virtuesecurity.com (company)
Managed by the OWASP® Foundation
owasp.org
Presentation slides: static.sched.com/hosted_files/owaspglobalappsecusa2025/0f/One%20Cluster%20to%20Rule%20Them%20All.pdf
As organizations scale their on-prem or cloud-native infrastructure, the attractiveness of a multi-tenant Kubernetes cluster is undeniable. The promise of reduced operational overhead, centralized management, and significant cost savings is pushing more and more teams to consolidate their workloads. But, how isolated are each of the development teams' access and workloads? What level of protection do solutions like Capsule and Kyverno provide, and where are the gaps? This talk dives deep into the unique security landscape of multi-tenant Kubernetes by analyzing the specific security needs of multi-tenant clusters and getting hands on with our newly released Kubernetes Penetration testing tool: VirtueKube. We will introduce theory and quickly move to live demonstrations and exploitation.
Nick Coblentz
Virtue Security
Application Pentester
Nick has been an application penetration tester for more than 15 years. He also volunteers his time to help moderate PortSwigger's discord server. nick.coblentz@gmail.com
linkedin.com/in/ncoblentz
virtuesecurity.com (company)
Managed by the OWASP® Foundation
owasp.org










