can-i gtfo?

Kubernetes RBAC Abuse Collection

View on GitHub

delete nodes

Abuses

Lateral Movement

Delete a node, which will result in the removal of all pods that are currently assigned to it. This process can be repeated until the pods are assigned to an attacker controlled node. This can be combined with the abuse of 'update/patch nodes' or 'update/patch nodes/status' permissions to prevent pods being assigned to non-attacker controlled nodes.