A kubeconfig bundles the API endpoint and a credential, a client certificate, a token, or an exec plugin. They leak constantly: in home directories, baked into images, in CI secrets and logs, and on bastion hosts. A recovered kubeconfig is direct API access as its identity, which is often a cluster or namespace admin.
find / -path '*/.kube/config' -o -name 'kubeconfig' 2>/dev/null
# Inspect what identity and cluster it holds, then use it
kubectl --kubeconfig ./found.config config view --minify
kubectl --kubeconfig ./found.config auth can-i --list
Exploitation notes#
- Developer and CI kubeconfigs frequently carry admin-level rights for convenience;
auth can-i --listconfirms the power. - Client certificates in a kubeconfig cannot be revoked by rotation the way tokens can, so a leaked cert is durable access until the CA is rotated.
- Images and CI artifacts are prime hunting grounds; combine with Secrets in image layers.