patch replicationcontrollers
A strategic merge patch reaches the same ReplicationController PodTemplateSpec as a full update, so this is an equivalent code-injection write rather than a lesser one.
Patching is the usual form in practice because it needs no prior read of the object.
Already-running pods are unaffected.
The template lands on the next replacement pod.
Contextual upgrade to T0:
T0 where the target ReplicationController runs in kube-system, or in any namespace whose pods carry cluster-privileged ServiceAccounts, because the poisoned template then executes with those credentials.
Elsewhere this is a foothold in the namespace rather than cluster compromise.
- API Group
- (core)
- Scope
- namespaced
- Audit Level
- Request
Escalation Paths
Patch or update an existing ReplicaSet or ReplicationController pod template
The change does not affect already-running pods.
ReplicaSet/RC only apply the template to pods they create afterward
Wait for or force pod replacement, using manual scale, pod deletion, node eviction, or voluntary disruption
The replacement pod is created from the poisoned template and inherits the workload's existing SA
Update alone forces replacement by scaling replicas (0 then 1).
Delete on pods is not required, it only makes replacement immediate without changing the replica count
Additional rights needed:

