Kubetier
← Permission Reference
T2

update replicasets/scale

The scale subresource carries only replicas, so a pod template sent to it is rejected under strict field validation and silently dropped otherwise, leaving the template untouched.

It cannot inject anything.

It does force pod replacement, which applies whatever template is current.

That activates poisoning done through update or patch on the full ReplicaSet, rather than being an escalation on its own.

API Group
apps
Scope
namespaced
Audit Level
Request
K8s docs ↗