services / Azure / Fleet hub Kubernetes initializer configurations

Initializer configurations are cluster-scoped Kubernetes admission-control objects on the Fleet Manager hub cluster that register interceptors which can gate or mutate objects during admission to the API server.

Admission-control configuration is a cluster-admin-tier security primitive; controlling it can influence every object created cluster-wide.


Microsoft.​ContainerService/​fleets/​admissionregistration.​k8s.​io/​initializerconfigurations/​write

Writing an initializer configuration registers an admission interceptor that can mutate objects admitted cluster-wide (inject privileged/mutated resources), enabling privilege escalation, tampering with admitted workloads, and bypass of other admission-based defenses.

Risks

Scope: CRITICAL

This privilege may grant access to sensitive data from a significant fraction of organizational functions, allow interruption of critical organizational services, or its exploit could lead to significant privilege escalation.

Links

  • https:​/​/​azure.​permissions.​cloud/​iam/​Microsoft.​ContainerService
  • https:​/​/​learn.​microsoft.​com/​en-​us/​azure/​role-​based-​access-​control/​resource-​provider-​operations
  • Contributed by P0 Security

    © 2023–present P0 Security and contributors to the IAM Privilege Catalog