OWASP K8s Vulnerable Cluster Playground
This playground presents a k3s cluster that has randomized security vulnerabilities injected based on the OWASP Kubernetes Top 10 list for 2025. Run a scan to find what's wrong, then fix it and get another random vulnerability automatically injected. Play as long as you like!

Using the kubernetes operator from this project to run a deliberately misconfigured k3s cluster.
Scan it using kubescape and fix it...then it'll automatically configure another randomized vulnerability so you can rinse and repeat as many times as you want.
The vulnerabilities are taken from the following OWASP Kubernetes 2025 list:
- K01: Insecure Workload Configurations
- K02: Overly Permissive Authorization Configurations (current implementation focuses on RBAC-driven authorization mistakes)
- K03: Secrets Management Failures
- K05: Missing Network Segmentation Controls
A real VM, not a container
Get root on a VM with its own kernel, so Docker, Kubernetes, and systemd just work.
Read the docs →
SSH from browser or CLI
Use the built-in web terminal, or connect with labctl ssh, plain ssh, scp, or rsync.
Read the docs →
Drive it with AI
Let Claude, Codex, or any MCP client start this playground and run commands in it.
Read the docs →
Expose HTTP(S) ports
Give any web app running inside the VM a public URL - for yourself or to share with others.
Read the docs →
Share terminals
Invite others into your terminal session, or open it yourself from another device.
Read the docs →
Customize with init scripts
Add shell scripts that run at boot to install packages, clone repos, or seed test data.
Read the docs →
Private networking
VMs reach the internet via NAT with no public IP; several VMs share bridge networks.
Read the docs →
Ephemeral or persistent
By default, VMs are destroyed when the session ends; enable persistence to keep the disks for next time.
Read the docs →
Built-in container registry
A private registry.iximiuz.com for every playground to share images across services and VMs.
Read the docs →