Ross ROSS = Recommend OSS · open-source software intelligence for agents

madhuakula/kubernetes-goat resource

Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀 observed · 2026-08-28

github.com/madhuakula/kubernetes-goat · homepage · HTML · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

57/100

  • Activity 77
  • Release rhythm 8
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 2281
  • days_rel: 729
  • days_push: 139
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

5756 stars · 1041 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Kubernetes Goat is an intentionally vulnerable-by-design Kubernetes cluster environment that serves as an interactive, hands-on playground for learning and practicing Kubernetes, container, and cloud-native security. It packages scenario-based attack and defense exercises deployable via Helm, aimed at attackers/red teams, defenders/blue teams, developers, DevOps teams, and security vendors.

Use cases

  • learn kubernetes security through hands-on practice
  • set up an intentionally vulnerable kubernetes cluster in an isolated lab
  • practice pentesting containers and kubernetes misconfigurations
  • train a devops or security team on container and cloud-native threats
  • demonstrate and evaluate security tools against realistic k8s attack scenarios
  • learn both attack techniques and defensive best practices for kubernetes

When to choose

  • you want a safe, scenario-based playground to learn or teach Kubernetes and container security
  • you are a red or blue teamer practicing exploitation, detection, and mitigation of real-world K8s misconfigurations
  • you are a vendor or educator needing an interactive environment to showcase security tooling effectiveness

When to avoid

  • you need a production-ready or hardened Kubernetes setup - it is deliberately vulnerable and must never run near production
  • you need an automated vulnerability scanner or compliance auditor rather than a manual training lab
  • you lack the ability to run an isolated cluster with admin access and kubectl/helm

Facets

learning-resource · maturity active

penetration-testing security developer-tools security penetration-testing cloud-computing education cloud self-hosted vulnerable-by-design kubernetes-security container-security hands-on-lab security-training devsecops red-team blue-team attack-defense-playground helm misconfiguration-scenarios cloud-native-security containers devops kubernetes docker

4 sources

Member repositories

RepositoryRoleHealth v2
madhuakula/kubernetes-goatmain57

For agents

markdown · JSON · MCP: product_card(name="madhuakula/kubernetes-goat")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem