Daily challenges →
🔐 DevSecOps hard ⚡ 80 XP

Why can permission to create pods in the kube-system namespace amount to full cluster compromise?

Pod creation implies the ability to set `serviceAccountName` to any account in the namespace — and kube-system hosts controllers with near-admin RBAC. The attacker pod simply reads the mounted token and uses it. This is a classic RBAC escalation path.

🌊 This is a free sample — 1015+ more questions on DevOps Ocean

Sign in free to practice the full question bank with daily challenges, XP, streaks, duels and a global leaderboard.

Practice the full bank — free →