Kubetier
← Permission Reference
T1

update daemonsets

An existing DaemonSet's PodTemplateSpec can be rewritten to run attacker-controlled images on every node.

With the default RollingUpdate strategy, this reconciles existing pods automatically.

With updateStrategy OnDelete, the change only lands on pods recreated afterward.

A kube-system DaemonSet is T0.

Contextual upgrade to T0:

Updating a kube-system DaemonSet injects code into core cluster components

API Group
apps
Scope
namespaced
Audit Level
Request

Escalation Paths

  1. Patch or update an existing Deployment, DaemonSet, or StatefulSet pod template, or a CronJob's jobTemplate.

  2. Add an attacker sidecar or replace the image.

  3. A Deployment rolls out at once, as do DaemonSets and StatefulSets under the default RollingUpdate strategy.

    Under updateStrategy OnDelete they wait for pod recreation.

  4. A CronJob applies the change on its next scheduled run with no extra trigger.

  5. Code runs with the workload's existing ServiceAccount, which is T0 for kube-system workloads.

Additional rights needed:

none
K8s docs ↗

See Also

Included in Built-in Roles

K8s docs ↗