In Kubernetes 1.31, 'read-only' pod permissions aren't truly read-only: websocket changes now allow users with GET rights to potentially execute commands, exposing a critical RBAC security nuance.
More: https://ku.bz/mgmFKY4xT
Post #1299
583