create deployments
Deployments embed a PodTemplateSpec, so creation is functionally equivalent to pod creation for all pod-based attack chains.
The controller creates the pods for you.
- API Group
- apps
- Scope
- namespaced
- Audit Level
- Request
Escalation Paths
Create a pod with privileged + hostPID or hostPath mounting /
Set spec.nodeName to a specific control plane node to force placement there.
Taints are scheduler-only checks, so no toleration is needed
chroot or nsenter into the host to gain root on the node
Read /etc/kubernetes/pki, steal kubelet cert or SA tokens.
This is T0 on the control plane
Additional rights needed:
Create a workload with serviceAccountName set to a privileged ServiceAccount in the same namespace.
Any controller-backed kind works, since the controller creates the pod.
The token is mounted at /var/run/secrets/kubernetes.io/serviceaccount/token, or projected explicitly by the manifest.
Reading it back needs a channel.
get on pods/log returns it if the container prints it to stdout.
Without pods/log, write it to /dev/termination-log and read terminated.message from the pod's status, which needs get on pods.
Neither verb is needed if the container sends the token outbound itself, which is why removing pods/log does not close this.
Authenticate as the ServiceAccount with the stolen token.
Additional rights needed:
