Kubernetes authorization is RBAC, and several verbs and resources let a modest identity become a stronger one. Some are explicit escalation primitives the API guards (escalate, bind, impersonate); others are powerful by second-order effect (create pods, approve certificates, request tokens). Map your rights with auth can-i --list, then take the shortest path up.
Subtopics#
- Over-permissive roles: wildcards and dangerous verbs granted outright.
- Escalate and bind verbs: granting yourself more through RBAC itself.
- Impersonation: acting as another, more privileged identity.
- Service account token abuse: reading and reusing other accounts' tokens.
- Pod creation to node: turning pod creation into node and cluster compromise.
- CSR approval: minting a client certificate for a privileged identity.
- TokenRequest API: minting tokens for service accounts you can act on.