can-i gtfo?

Kubernetes RBAC Abuse Collection

View on GitHub

patch pods/ephemeralcontainers

Abuses

Container Escape

Patch ephemeral containers with host access capabilities to escape container boundaries

# Patch pod with ephemeral container that has host network access
# Patch pod with ephemeral container that mounts host filesystem

Lateral Movement

Patch ephemeral containers on other nodes with host access capabilities to escape container boundaries

# Patch pod with ephemeral container that has host network access
# Patch pod with ephemeral container that mounts host filesystem