Azure Kubernetes Service bridges the Azure management plane and the Kubernetes API, so an Azure foothold becomes in-cluster power two ways: pull the cluster's admin kubeconfig, or run commands in the cluster through the management plane. Separately, each node pool carries a managed identity that a pod can reach through IMDS.
Pages#
- Cluster access:
listClusterAdminCredentialandmanagedClustersrunCommand. - Node identity: the node pool kubelet and managed identity through IMDS.
Generic in-cluster Kubernetes attacks (RBAC, service-account tokens, pod escape) live in the Containers area; these pages stay on the AKS cloud-plane and node-identity angle.