Compute

GCP compute is where a project's service accounts are most exposed: every Compute Engine VM and GKE node runs as a service account whose token the metadata server hands out on request, and the permission to write a VM's metadata is the permission to run code on it. The surfaces below turn control of, or reach to, an instance into that instance's identity.

What folds in here#

  • Compute Engine: metadata and SSH-key injection, OS Login, and the instance's attached service-account scopes.
  • GKE: pulling cluster credentials from the cloud side, and stealing the node pool's service-account token.

Deploying a new instance to run as a privileged service account is a privilege-escalation path and lives under identity actAs; the pages here cover instances and clusters that already exist. Generic in-cluster Kubernetes attacks live in the Containers area and are cross-referenced, not duplicated.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more