Kubetier
← Permission Reference
T1

create pods

Setting serviceAccountName to a privileged SA mounts its token into the pod.

Reading it lets you reuse the SA's identity.

Contextual upgrade to T0:

Permission covers kube-system and pod is configured to run as a high-privilege controller ServiceAccount (e.g. kube-controller-manager), exposing near-cluster-admin credentials

API Group
(core)
Scope
namespaced
Audit Level
Request

Escalation Paths

  1. Create a workload with serviceAccountName set to a privileged ServiceAccount in the same namespace.

    Any controller-backed kind works, since the controller creates the pod.

  2. The token is mounted at /var/run/secrets/kubernetes.io/serviceaccount/token, or projected explicitly by the manifest.

  3. Reading it back needs a channel.

    get on pods/log returns it if the container prints it to stdout.

  4. Without pods/log, write it to /dev/termination-log and read terminated.message from the pod's status, which needs get on pods.

  5. Neither verb is needed if the container sends the token outbound itself, which is why removing pods/log does not close this.

  6. Authenticate as the ServiceAccount with the stolen token.

Additional rights needed:

none
K8s docs ↗
K8s docs ↗