Sidecars

A sidecar shares the pod's network and trust context, which is what makes it useful and what makes it risky.

It can see the traffic, hold the identity and reach what the main container reaches. That is the point for a proxy or a logging agent, and it means a compromised sidecar is a compromised workload. They are frequently third-party images added with less scrutiny than the application itself.

Checked against the primary source.

More on Containers & Kubernetes