Open cardosec

Case 06EFAC · Cloud · L4 Advanced

Kubernetes RBAC

Practise as: Explain it · Interview

Interview questionWhich Kubernetes RBAC permissions are effectively cluster-admin in disguise?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. RBAC binds Roles/ClusterRoles to users, groups or service accounts, per namespace or cluster-wide
  2. Dangerous verbs: create pods (run privileged pods), get secrets, escalate/bind, impersonate, nodes/proxy
  3. Default service account tokens mounted in every pod give an attacker API access from any compromised container
  4. Set automountServiceAccountToken: false where unused and give each workload its own minimal account
  5. Audit with kubectl auth can-i --list and review ClusterRoleBindings to system:authenticated

If the interviewer pushes back

  • Why is "create pods" in a namespace often equivalent to reading every secret in it?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.