A pod compromise becomes a control-plane problem when workload identity turns execution into transitive authority. Kubernetes service-account tokens are not universal master keys, but permissive RBAC, workload federation, cloud IAM, and reachable credentials can connect one application incident to cluster and cloud impact.
This AlphaHunt Deep Research piece maps the attacker sequence, the escalation-relevant permissions, the telemetry needed to reconstruct identity movement, and the checkpoints defenders can use to break the path.
Read the full analysis.