Impersonation

Impersonation lets a caller run a request as someone else by setting impersonation headers, which kubectl exposes as --as and --as-group. An identity granted the impersonate verb on users, groups, or service accounts can borrow their permissions, and impersonating a privileged group like system:masters is cluster-admin.

bash
kubectl auth can-i impersonate users
kubectl auth can-i impersonate groups

# Act as a privileged group or admin user
kubectl --as=admin get secrets -A
kubectl --as=null --as-group=system:masters get nodes

Exploitation notes#

  • Impersonating the group system:masters grants full cluster-admin, since that group is hard-wired to it.
  • Impersonation can be scoped to specific names; where it is, enumerate which users, groups, or service accounts you may impersonate.
  • It leaves the request attributed to the impersonated identity, which is also why it is powerful: you act fully as them.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more