can-i gtfo?

Kubernetes RBAC Abuse Collection

View on GitHub

create pods/eviction

Abuses

Lateral Movement

Evict pods from nodes until they are assigned to an attacker controlled node. Can be combined with the abuse of 'update/patch nodes' or 'update/patch nodes/status' permissions to prevent pods being assigned to non-attacker controlled nodes.