Cloud Build runs every build as the Cloud Build service account (<project-number>@cloudbuild.gserviceaccount.com), which by default has historically been granted the project Editor role. Anyone who can start a build, or plant a trigger that starts one, therefore runs arbitrary steps as a near-admin principal. This makes Cloud Build one of the strongest GCP privilege-escalation and persistence surfaces.
Pages#
- Build service account: starting a build whose steps exfiltrate the build SA token and act with its roles.
- Build triggers: planting or editing repository triggers so pushes run attacker steps as the build SA.