Kubernetes RBAC Privilege Escalation thumbnail

Kubernetes RBAC Privilege Escalation

By Richard Augenti

Escalate from a limited service account to cluster-admin through over-granted RBAC verbs, then rewrite the roles and prove the same path is closed.

Browse
Skill Level: Advanced Duration: 60 min Identity and AccessKubernetesDevSecOps
Sign in to start

Free to browse. Takes about 60 minutes once you start.

Lab Overview

The platform's CI deployer ServiceAccount was granted a role that does far more than deploy. Among its permissions is the ability to create ClusterRoleBindings and to bind any ClusterRole - which is, in practice, the ability to make itself cluster-admin.

In this lab you perform that escalation, then rewrite the role down to the least privilege a deployer actually needs and confirm the path is dead while real deploys still work. The bind verb and ClusterRoleBinding creation are among the most dangerous grants in RBAC, and this is what they look like when they are handed out by accident.

Everything runs against a local kind cluster on your own lab VM. The lab tooling refuses to touch any cluster whose context is not a kind cluster, so you cannot aim this at anything real by accident.

What to Expect

  • Environment: a single Ubuntu machine you connect to over SSH, with a local kind cluster and the over-granted deployer role already in place.
  • Access: SSH credentials are generated for your session and shown in the workspace. They are destroyed when the lab ends.
  • Guard rail: the lab tooling refuses to run against any context that is not a kind cluster, so the escalation cannot be pointed at a real cluster.
  • Progress: your work is not saved. If the lab expires or you quit, the machine, the cluster and everything on them are destroyed.

What are hands-on labs?

A lab is a real environment, not a simulation. You get a live machine with the tooling already installed, a task taken from production work, and root access to take it apart. Nothing is mocked, nothing is multiple choice. It either works or it doesn't.

Real tooling

The same commands you would run at work, on a machine that is already set up for them. No screenshots, no sandboxed toy version.

Break it freely

Everything is disposable. When the clock runs out the environment is destroyed with everything in it, so there is no reason to be careful.

Useful on Monday

Built by engineers who run these systems in production. Skills you can apply to your own stack the same week, not exam preparation.

Browse labs