Kubernetes Bug Bounty
CNCF-funded bug bounty for Kubernetes components and the related assets listed on HackerOne.
Tags: vendor, hackerone, opensource
- Program model
- Vendor on HackerOne
- Regions
- Global
- Payout
- Varies by program
Specialties: cloud, opensource, api
How to approach it
Scope first. Report through the HackerOne program. Do not test clusters you do not operate.
- Use the project security page for process, then the HackerOne asset list for scope.
- A bug in your own local cluster is not a bug in someone else's production cluster.