Why can permission to create pods in the kube-system namespace amount to full cluster compromise?
Pod creation implies the ability to set `serviceAccountName` to any account in the namespace — and kube-system hosts controllers with near-admin RBAC. The attacker pod simply reads the mounted token and uses it. This is a classic RBAC escalation path.
🌊 This is a free sample — 1015+ more questions on DevOps Ocean
Sign in free to practice the full question bank with daily challenges, XP, streaks, duels and a global leaderboard.