Workflow: Kubernetes RBAC Privilege Mapping
Enumerate principals (users, groups, ServiceAccounts), the roles bound to them, and the effective verbs/resources. Identify over-permissioned principals and lateral-movement paths.
Steps
Harvest RBAC objects:
kubectl get clusterroles -o json > clusterroles.json kubectl get roles -A -o json > roles.json kubectl get clusterrolebindings -o json > clusterrolebindings.json kubectl get rolebindings -A -o json > rolebindings.json kubectl get sa -A -o json > serviceaccounts.jsonBuild principal → role → rules graph. For each binding, resolve
subjects[]→roleRef→ rules (verbs × apiGroups × resources × resourceNames).Flag high-risk grants:
cluster-adminbindings outside system namespaces*verb on*resource (any scope)impersonateverb — lets the subject become any user/SAescalateorbindverb onroles/clusterroles— privilege escalationcreateonpods+getonsecrets(classic SA token harvest path)exec,attach,portforwardon pods in productioncreateonnodes/nodes/proxy(node-level exposure)patch/updateonvalidatingwebhookconfigurations/mutating…(admission bypass)*onpods/ephemeralcontainers(stealth debug injection)
Path-finding to cluster-admin (attack graph): For each low-privilege SA, BFS through RBAC graph:
- Any verb that yields a higher-privileged token (
get secrets) - Any pod-creation verb scoped to a namespace hosting privileged SAs
create tokenrequeston a higher-privileged SA Report shortest path and required steps as reproduction.
- Any verb that yields a higher-privileged token (
Tool assistance:
# rbac-tool (insights-engineering) rbac-tool who-can get secrets rbac-tool policy-rules -e '^system:' rbac-tool viz --cluster-context <ctx> # graphviz output # kubectl-who-can kubectl who-can create pods -n production # krane (static RBAC analyzer) krane reportEmit findings with
affected.resource_kind∈{ClusterRoleBinding, RoleBinding, ClusterRole, Role},affected.service_account,affected.namespace.
Parallelism
- RBAC object fetches: parallel
- Per-principal graph expansion: parallel (stateless)
- Tool runs (rbac-tool + krane): parallel
Reasoning Budget
Extended thinking for privilege-graph traversal. Finding the shortest attack path from a compromised SA to cluster-admin is non-trivial and benefits from deep reasoning. Scanning for single-hop violations can use minimal budget.