Overview

FieldValue
ID1033
NameManage Deployments cluster-wide (potential for privileged pod execution)
Risk CategoryElevation of Privilege
Risk LevelCritical
Role TypeClusterRole
API Groupsapps
Resourcesdeployments
Verbscreate, update, patch, delete
TagsPersistence PrivilegeEscalation Tampering WorkloadLifecycle

Description

Allows creating, updating, or deleting Deployments across all namespaces. Deployments manage pod replicas, and this permission can be used to deploy pods with privileged settings, leading to code execution, privilege escalation, persistence, and tampering with cluster workloads.