Kubetier
  1. Patch or update an existing Deployment, DaemonSet, or StatefulSet pod template, or a CronJob's jobTemplate.

  2. Add an attacker sidecar or replace the image.

  3. A Deployment rolls out at once, as do DaemonSets and StatefulSets under the default RollingUpdate strategy.

    Under updateStrategy OnDelete they wait for pod recreation.

  4. A CronJob applies the change on its next scheduled run with no extra trigger.

  5. Code runs with the workload's existing ServiceAccount, which is T0 for kube-system workloads.

Rights needed, any one set:

K8s docs ↗