TGViewer
DevOps&SRE Library DevOps&SRE Library @devopslibrary · 19.9K subscribers
Post #7638 3.3K
nodes/proxy GET: One Kubernetes permission too many

The nodes/proxy GET RBAC permission allows any ServiceAccount to execute code inside any Pod in the cluster, without leaving a single trace in the audit logs. This article details the issue, how to check if you are vulnerable, the fixes to apply, and the preventive measures you can put in place if you can't patch right away.


https://blog.zwindler.fr/en/2026/05/19/nodes/proxy-get-one-kubernetes-permission-too-many
More from @devopslibrary
  1. Sep 23, 2026Building a Real k6 Test Suite Against a Live Kubernetes App In part 1 I covered k6's philo…
  2. Sep 22, 2026My Experiments with MCP: Moving Beyond the "Agent Wrapper" I'm currently working with a cl…
  3. Sep 22, 2026Your AI just deleted the wrong deployment. Now what? Picture this. A developer asks an AI…
  4. Sep 21, 2026Kafka on Kubernetes: Performance Lessons for Any Disk-Heavy Data Service We recently start…
  5. Sep 21, 2026What the Popularity of Emerging Tools Tells Us About Kubernetes' Future Kubernetes has mat…
  6. Sep 20, 2026How Uber Conquered Database Overload: The Journey from Static Rate-Limiting to Intelligent…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →