Kubetier
T2system:kube-dnscluster

CoreDNS/kube-dns identity with list/watch access to Services, Endpoints, EndpointSlices, and Namespaces cluster-wide to answer DNS queries for workloads.

  • Compromise of the CoreDNS ServiceAccount can expose cluster service-discovery topology and, with config write access, enable DNS poisoning.

  • The common poisoning vector is write access to the CoreDNS ConfigMap in kube-system, not this read/list role by itself.

Permissions (1)
apiGroupresources / urlsverbs
""endpoints, serviceslist watch
Audit: MetadataK8s docs ↗