patch statefulsets
A strategic merge patch reaches the same StatefulSet PodTemplateSpec as a full update, so this is an equivalent code-injection write rather than a lesser one.
Patching is the usual form in practice because it needs no prior read of the object.
The rollout applies it to running pods.
Contextual upgrade to T0:
Updating a kube-system StatefulSet injects code into core cluster components
- API Group
- apps
- Scope
- namespaced
- Audit Level
- Request
Escalation Paths
Patch or update an existing Deployment, DaemonSet, or StatefulSet pod template, or a CronJob's jobTemplate.
Add an attacker sidecar or replace the image.
A Deployment rolls out at once, as do DaemonSets and StatefulSets under the default RollingUpdate strategy.
Under updateStrategy OnDelete they wait for pod recreation.
A CronJob applies the change on its next scheduled run with no extra trigger.
Code runs with the workload's existing ServiceAccount, which is T0 for kube-system workloads.
Additional rights needed:

