Lab 02 — RBAC Exploitation
Mission Information
Section titled “Mission Information”| Property | Value |
|---|---|
| Lab Name | RBAC Exploitation |
| Module | Module 05 — Kubernetes Offensive Security |
| Difficulty | Intermediate |
| Estimated Time | 90–120 Minutes |
| Lab Type | Guided Hands-on Lab |
| Platform | Kubernetes (Minikube / Kind / Amazon EKS / Azure AKS / Google GKE) |
| Prerequisites | Lessons 01–04 and Lab 01 |
| Skills Covered | RBAC Assessment, Identity Review, Service Accounts, Authorization Review, Enterprise Governance |
Mission Brief
Section titled “Mission Brief”CloudNova Technologies has been contracted to perform an authorized Kubernetes security assessment for a multinational organization.
During the initial reconnaissance phase, the consulting team identified hundreds of Kubernetes identities, Service Accounts, and RoleBindings across multiple namespaces.
Management is concerned that excessive permissions and weak identity governance may allow unauthorized access to production workloads.
Your objective is to review the Kubernetes authorization model, identify RBAC weaknesses, assess privilege assignments, and prepare a professional security assessment report.
This engagement focuses on assessment and validation, not unauthorized exploitation.
Learning Objectives
Section titled “Learning Objectives”By completing this lab, you will learn how to:
- Review Kubernetes RBAC.
- Enumerate Roles and ClusterRoles.
- Review RoleBindings.
- Review ClusterRoleBindings.
- Assess Service Accounts.
- Identify excessive permissions.
- Validate Least Privilege.
- Build an enterprise identity inventory.
- Produce consulting-quality findings.
Enterprise Scenario
Section titled “Enterprise Scenario”The customer operates:
- Multiple production clusters
- Hundreds of developers
- CI/CD automation
- DevOps teams
- Platform engineering teams
Over several years, numerous permissions have been granted to users and automation accounts.
The organization requires an independent review to determine whether access remains appropriate.
Lab Architecture
Section titled “Lab Architecture”Enterprise Kubernetes Cluster
│
Kubernetes API Server
│
RBAC
├── Roles ├── ClusterRoles ├── RoleBindings ├── ClusterRoleBindings
│
Service Accounts
│
Namespaces
│
ApplicationsMission Tasks
Section titled “Mission Tasks”Task 01 — Review Kubernetes RBAC
Section titled “Task 01 — Review Kubernetes RBAC”Objective
Section titled “Objective”Understand the authorization model used within the cluster.
Review:
- Roles
- ClusterRoles
- RoleBindings
- ClusterRoleBindings
Document:
- Administrative roles
- Namespace-specific roles
- Cluster-wide permissions
Task 02 — Review Roles
Section titled “Task 02 — Review Roles”Inventory every Role.
Document:
- Role name
- Namespace
- Purpose
- Permissions
- Owner
Review whether permissions align with business requirements.
Task 03 — Review ClusterRoles
Section titled “Task 03 — Review ClusterRoles”Inventory every ClusterRole.
Identify:
- Administrative roles
- Built-in roles
- Custom roles
- Wildcard permissions
Document:
- Scope
- Business purpose
- Assigned identities
Task 04 — Review RoleBindings
Section titled “Task 04 — Review RoleBindings”Review:
- RoleBindings
- Assigned users
- Assigned groups
- Assigned Service Accounts
Determine whether namespace permissions follow the Principle of Least Privilege.
Task 05 — Review ClusterRoleBindings
Section titled “Task 05 — Review ClusterRoleBindings”Assess every ClusterRoleBinding.
Document:
- Identity
- ClusterRole assigned
- Business justification
- Administrative access
Highlight unnecessary cluster-wide permissions.
Task 06 — Review Service Accounts
Section titled “Task 06 — Review Service Accounts”Inventory:
- Service Account names
- Namespace
- Assigned Roles
- Workload association
Review:
- Administrative permissions
- Token usage
- Business ownership
Task 07 — Review Privileged Identities
Section titled “Task 07 — Review Privileged Identities”Identify:
- Cluster administrators
- Namespace administrators
- Automation accounts
- Monitoring accounts
- CI/CD identities
Determine:
- Business owner
- Access justification
- Last review date
- Operational necessity
Task 08 — Validate Least Privilege
Section titled “Task 08 — Validate Least Privilege”Review whether identities have:
- Only required permissions
- Appropriate namespace access
- Separation of duties
- Limited administrative rights
Document identities requiring remediation.
Task 09 — Identify Security Findings
Section titled “Task 09 — Identify Security Findings”Record observations including:
- Excessive permissions
- Wildcard roles
- Shared Service Accounts
- Dormant administrative accounts
- Unnecessary ClusterRoleBindings
- Weak namespace isolation
- Missing ownership documentation
- Poor RBAC governance
Task 10 — Prepare Identity Assessment Report
Section titled “Task 10 — Prepare Identity Assessment Report”Produce:
- Identity inventory
- RBAC inventory
- Administrative access review
- Risk assessment
- Remediation recommendations
Expected Deliverables
Section titled “Expected Deliverables”RBAC Inventory
Section titled “RBAC Inventory”Document:
- Roles
- ClusterRoles
- RoleBindings
- ClusterRoleBindings
Identity Inventory
Section titled “Identity Inventory”Include:
- Users
- Groups
- Service Accounts
- Administrative identities
Privileged Access Review
Section titled “Privileged Access Review”Document:
- Administrative accounts
- Cluster administrators
- Namespace administrators
- Automation identities
Security Findings
Section titled “Security Findings”Include:
- Finding
- Risk Rating
- Business Impact
- Technical Impact
- Recommendation
- Priority
Executive Summary
Section titled “Executive Summary”Summarize:
- Overall RBAC maturity
- Identity governance posture
- High-risk permissions
- Recommended improvements
Success Criteria
Section titled “Success Criteria”You have successfully completed this lab when you can:
- Inventory all RBAC resources.
- Identify privileged identities.
- Review Service Account permissions.
- Validate Least Privilege.
- Produce a professional RBAC assessment report.
- Recommend governance improvements.
Skills Gained
Section titled “Skills Gained”After completing this lab, you will be able to:
- Assess Kubernetes authorization controls.
- Review enterprise RBAC implementations.
- Identify excessive permissions.
- Evaluate identity governance.
- Produce consulting-quality security findings.
- Recommend RBAC hardening strategies.
Challenge Exercises
Section titled “Challenge Exercises”If time permits:
- Identify identities with cluster-wide administrative access.
- Compare permissions across production and development namespaces.
- Review custom ClusterRoles for unnecessary permissions.
- Validate separation of duties between platform, development, and operations teams.
- Prioritize RBAC findings based on business impact.
Lab Summary
Section titled “Lab Summary”In this lab, you performed a structured assessment of Kubernetes Role-Based Access Control (RBAC) using the GoHackersCloud Enterprise Assessment Methodology.
You reviewed authorization objects, assessed Service Accounts, identified excessive permissions, validated Least Privilege, and produced professional consulting deliverables. These activities mirror the identity and authorization reviews performed during real-world Kubernetes security consulting engagements.
Next Lab
Section titled “Next Lab”➡️ Lab 03 — Kubernetes Secrets Assessment
In the next lab, you will assess Kubernetes Secrets management by reviewing secret storage, Service Account tokens, credential governance, encryption, and access controls to evaluate how effectively sensitive information is protected within an enterprise Kubernetes environment.