T1
Developer exec access to namespace admin
Namespace adminEvery credential in a namespace, reached from an exec grant meant for debugging. The pod you exec into runs its own ServiceAccount, and that token is yours the moment you have a shell.
- RBAC
- runtime
- governed by RBAC
- not governed by RBAC
- →
- →


Sources: kubernetes.io, kubernetes.io