T2system:kube-dnscluster
CoreDNS/kube-dns identity with list/watch access to Services, Endpoints, EndpointSlices, and Namespaces cluster-wide to answer DNS queries for workloads.
- →
Compromise of the CoreDNS ServiceAccount can expose cluster service-discovery topology and, with config write access, enable DNS poisoning.
- →
The common poisoning vector is write access to the CoreDNS ConfigMap in kube-system, not this read/list role by itself.
Permissions (1)
| apiGroup | resources / urls | verbs |
|---|---|---|
| "" | endpoints, services | list watch |
Audit: MetadataK8s docs ↗
