create priorityclasses
A PriorityClass with globalDefault true silently raises the priority of every future pod that sets no priorityClassName, cluster-wide, without needing pods create permission.
High-priority PriorityClasses also let pods using them preempt (evict) lower-priority pods across namespace boundaries once a node is full, though exploiting that preemption needs a separate pods create permission.
PriorityClass alone cannot cause eviction.
Contextual upgrade to T1:
An ordinary nodeSelector on the attacker pod turns high priority into precise cross-namespace eviction. A chosen victim is preempted off a named node and the attacker pod takes its place.
No RBAC access to the victim namespace is needed.
- API Group
- scheduling.k8s.io
- Scope
- cluster
- Audit Level
- Request
Escalation Paths
Create a PriorityClass with a very high value and preemptionPolicy PreemptLowerPriority.
Create a pod referencing that PriorityClass, with requests large enough that it only fits by evicting a running pod.
The scheduler preempts a lower-priority victim to make room.
This crosses namespaces, because priority is compared node-wide and the scheduler has no notion of which namespace owns the capacity.
The gain is scheduled capacity taken from another team, not credentials or API permissions.
Additional rights needed:
· a PriorityClass preempts nothing until a workload references it, and a controller-backed workload verb can stand in for create pods
Create a PriorityClass with globalDefault true.
Every pod created afterwards with no priorityClassName inherits that priority, cluster-wide.
No pod create verb is needed.
The effect lands on other people's future workloads, not on one the attacker submits.
Existing pods keep the priority they were admitted with, so the change is invisible until the next rollout.
This only works where no global default exists yet.
Admission rejects a second one outright, so displacing an existing default would additionally need delete on it
Additional rights needed:

