Cluster admin has a very large blast radius

There is no partial compromise of a cluster administrator.

Every namespace, every secret, every node, every workload, plus the ability to remove the evidence. Treating it as an ordinary elevated role, handed out to a team, is how one credential becomes the whole platform. Just-in-time issuance applies here as strongly as anywhere.

More on Kubernetes