Patch or update an existing Deployment, DaemonSet, or StatefulSet pod template, or a CronJob's jobTemplate.
Add an attacker sidecar or replace the image.
A Deployment rolls out at once, as do DaemonSets and StatefulSets under the default RollingUpdate strategy.
Under updateStrategy OnDelete they wait for pod recreation.
A CronJob applies the change on its next scheduled run with no extra trigger.
Code runs with the workload's existing ServiceAccount, which is T0 for kube-system workloads.
Rights needed, any one set:
· any one; each owns a pod template
· any one; each owns a pod template
· any one; each owns a pod template
· any one; each owns a pod template
