With a token, read everything the identity allows. The API server exposes the full cluster state, and even a limited identity often reads secrets, roles, and bindings that chart the next move.
k get namespaces
k get pods -A -o wide
k get secrets -A # tokens, registry creds, app secrets
k get roles,rolebindings,clusterroles,clusterrolebindings -A
k get nodes -o wide
Exploitation notes#
get secretsis the highest-value read: service-account tokens and application credentials live there, and one readable secret often grants a stronger identity.- The roles and bindings are the escalation map; read them to find who can
escalate,impersonate, or create pods, as in RBAC privilege escalation. - Where direct reads are denied,
auth can-i --liststill reveals the shape of your permissions without triggering access failures on each resource.