# madhuakula/kubernetes-goat

Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground 🚀

Repository: https://github.com/madhuakula/kubernetes-goat
Canonical: https://ross.abutalabs.com/products/kubernetes-goat
Homepage: https://madhuakula.com/kubernetes-goat
Language: HTML
License: MIT
License Family: permissive
Topics: kubernetes, vulnerable-app, security, hacking, pentesting, infrastructure, cloud-security, docker, container, kubernetes-goat, devsecops, cloudsecurity, kubernetes-security, container-security, owasp, cloud-native, k8s, blueteam, redteam
Last push: 2026-04-16T22:11:11+00:00

## Health v2 (maintenance only)
Score: 57/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 77, release rhythm 8, longevity 100
- inputs: {"age_days": 2281, "days_push": 139, "days_rel": 729, "gap_med": null, "n_releases_24m": 1}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 5756, forks 1041 (observed 2026-08-28T04:09:29.225439+00:00)

## What it is
Kubernetes Goat is an intentionally vulnerable-by-design Kubernetes cluster environment that serves as an interactive, hands-on playground for learning and practicing Kubernetes, container, and cloud-native security. It packages scenario-based attack and defense exercises deployable via Helm, aimed at attackers/red teams, defenders/blue teams, developers, DevOps teams, and security vendors.

## Use cases
- learn kubernetes security through hands-on practice
- set up an intentionally vulnerable kubernetes cluster in an isolated lab
- practice pentesting containers and kubernetes misconfigurations
- train a devops or security team on container and cloud-native threats
- demonstrate and evaluate security tools against realistic k8s attack scenarios
- learn both attack techniques and defensive best practices for kubernetes

## When to choose
- you want a safe, scenario-based playground to learn or teach Kubernetes and container security
- you are a red or blue teamer practicing exploitation, detection, and mitigation of real-world K8s misconfigurations
- you are a vendor or educator needing an interactive environment to showcase security tooling effectiveness

## When to avoid
- you need a production-ready or hardened Kubernetes setup - it is deliberately vulnerable and must never run near production
- you need an automated vulnerability scanner or compliance auditor rather than a manual training lab
- you lack the ability to run an isolated cluster with admin access and kubectl/helm

## Facets
- artifact type: learning-resource
- maturity: active
- function: penetration-testing, security, developer-tools
- domain: security, penetration-testing, cloud-computing, education
- platform: cloud, self-hosted
- tags: vulnerable-by-design, kubernetes-security, container-security, hands-on-lab, security-training, devsecops, red-team, blue-team, attack-defense-playground, helm, misconfiguration-scenarios, cloud-native-security, containers, devops, kubernetes, docker

## Member repositories
- madhuakula/kubernetes-goat (main) score 57

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:09:29.225439+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T17:53:16.387781+00:00, confidence not recorded.
  - readme: https://github.com/madhuakula/kubernetes-goat (fetched 2026-08-28T04:09:29.225439+00:00, sha bf4dbb67e71b)
  - homepage: https://madhuakula.com/kubernetes-goat (fetched 2026-08-29T08:48:29.449878+00:00, sha f7d09258a0b1)
  - site_page: https://madhuakula.com/kubernetes-goat/docs/wall-of-love (fetched 2026-08-29T08:48:29.455028+00:00, sha 52931432c72d)
  - site_page: https://madhuakula.com/kubernetes-goat/docs (fetched 2026-08-29T08:48:29.452619+00:00, sha f8bf7454c0c5)
- Data as of 2026-08-30T08:39:29.467469+00:00.
