RBAC privilege escalation

Kubernetes authorization is RBAC, and several verbs and resources let a modest identity become a stronger one. Some are explicit escalation primitives the API guards (escalate, bind, impersonate); others are powerful by second-order effect (create pods, approve certificates, request tokens). Map your rights with auth can-i --list, then take the shortest path up.

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more