Impersonation lets a caller run a request as someone else by setting impersonation headers, which kubectl exposes as --as and --as-group. An identity granted the impersonate verb on users, groups, or service accounts can borrow their permissions, and impersonating a privileged group like system:masters is cluster-admin.
kubectl auth can-i impersonate users
kubectl auth can-i impersonate groups
# Act as a privileged group or admin user
kubectl --as=admin get secrets -A
kubectl --as=null --as-group=system:masters get nodes
Exploitation notes#
- Impersonating the group
system:mastersgrants full cluster-admin, since that group is hard-wired to it. - Impersonation can be scoped to specific names; where it is, enumerate which users, groups, or service accounts you may impersonate.
- It leaves the request attributed to the impersonated identity, which is also why it is powerful: you act fully as them.