Kubetier
← Permission Reference
T1

patch deployments

A strategic merge patch reaches the same Deployment PodTemplateSpec as a full update, so this is an equivalent code-injection write rather than a lesser one.

Patching is the usual form in practice because it needs no prior read of the object.

The rollout applies it to running pods.

Contextual upgrade to T0:

Updating a kube-system Deployment injects code into core cluster components

API Group
apps
Scope
namespaced
Audit Level
Request

Escalation Paths

  1. Patch or update an existing Deployment, DaemonSet, or StatefulSet pod template, or a CronJob's jobTemplate.

  2. Add an attacker sidecar or replace the image.

  3. A Deployment rolls out at once, as do DaemonSets and StatefulSets under the default RollingUpdate strategy.

    Under updateStrategy OnDelete they wait for pod recreation.

  4. A CronJob applies the change on its next scheduled run with no extra trigger.

  5. Code runs with the workload's existing ServiceAccount, which is T0 for kube-system workloads.

Additional rights needed:

none
K8s docs ↗

See Also

K8s docs ↗