GKE authenticates to the Kubernetes API with a Cloud IAM token, so the Cloud IAM permission container.clusters.get (via container.clusters.getCredentials) is enough to obtain a working kubeconfig. What you can then do inside the cluster depends on the Kubernetes RBAC bound to your identity, but the broad roles/container.admin or roles/container.clusterAdmin map straight to cluster-admin.
Getting a kubeconfig#
# list clusters you can reach, then pull credentials
gcloud container clusters list
gcloud container clusters get-credentials <cluster> --zone <zone> --project <project>
# now talk to the API with your GCP identity as the bearer
kubectl auth can-i --list
kubectl get secrets -A
Exploitation notes#
roles/container.admingrants Kubernetes cluster-admin through RBAC; evencontainer.viewerplusgetCredentialsoften reads secrets across namespaces.- A private cluster still answers if you can reach its control-plane endpoint (from a VM in the VPC, a peered network, or an authorized network you landed in).
- Once inside, pivot to pod service accounts and the node identity; generic in-cluster technique lives in the Containers area.
Tools#
- gcloud (
container clusters get-credentials). - kubectl, Peirates for in-cluster movement once you hold the kubeconfig.