Cluster admin has a very large blast radius
There is no partial compromise of a cluster administrator.
Every namespace, every secret, every node, every workload, plus the ability to remove the evidence. Treating it as an ordinary elevated role, handed out to a team, is how one credential becomes the whole platform. Just-in-time issuance applies here as strongly as anywhere.
More on Kubernetes
- A container is isolation, not a tiny virtual machinePartitions, not buildings
- Kubernetes RBAC controls API actions, not what a running container can then doChecked at the hatch, not inside the room
- A pod service account is an identityA badge on the same rail
- NetworkPolicy needs an enforcement engineHinges, but no gate
- Admission control can stop risky objects before they runStopped on the chute
- Privileged containers weaken the host boundaryThe floor is the boundary
