The most common escalation is simply a role that grants too much. Wildcards (* resources or verbs), secrets read, pods/exec, and write access to roles or rolebindings are each enough to climb. Enumerate your effective rights and look for these.
kubectl auth can-i --list
kubectl auth can-i get secrets
kubectl auth can-i create pods
kubectl auth can-i '*' '*' # wildcard = effectively admin in scope
Exploitation notes#
get secretsyields other identities' tokens, often a shortcut straight to a more privileged service account.create podsorpods/execescalates through the node, see Pod creation to node.- Write access to roles or bindings is self-escalation, bounded by the escalate and bind guards in Escalate and bind verbs.