Kubernetes RBAC controls API actions, not what a running container can then do
Permissions govern what can be asked of the cluster, not what happens inside the container once it is running.
A tightly restricted role can still schedule a pod that does whatever it likes on the node, subject to pod security settings. The two controls sit at different layers and people regularly assume one covers the other, which leaves a gap exactly where workloads execute.
More on Kubernetes
- A container is isolation, not a tiny virtual machinePartitions, not buildings
- A pod service account is an identityA badge on the same rail
- NetworkPolicy needs an enforcement engineHinges, but no gate
- Admission control can stop risky objects before they runStopped on the chute
- Privileged containers weaken the host boundaryThe floor is the boundary
- Mutable image tags can move underneath youSame ticket, different coat
