Google Kubernetes Engine sits on the seam between Cloud IAM and Kubernetes RBAC, and both ends are attackable from the cloud side. A Cloud IAM permission (container.clusters.getCredentials) hands you a kubeconfig for the cluster; a shell on a node gives you the node pool's service-account token from the metadata server. The pages here cover that cloud-to-cluster and node-identity angle.
What folds in here#
- Cluster access:
container.clusters.getCredentialsand the get-credentials flow to reach the Kubernetes API. - Node identity: stealing the node pool's service-account token from metadata, and Workload Identity abuse.
Generic in-cluster Kubernetes attacks (RBAC, service-account tokens, pod escape) live in the Containers area; these pages stay on the GCP control-plane and node-identity angle.