Create a pod with privileged + hostPID or hostPath mounting /
Set spec.nodeName to a specific control plane node to force placement there.
The NoSchedule taint kubeadm puts on those nodes is a scheduler check only, so a directly bound pod needs no toleration
chroot or nsenter into the host to gain root on the node
Read /etc/kubernetes/pki, steal kubelet cert or SA tokens.
This is T0 on the control plane
Rights needed, any one set:

