Config Connector (KCC) removes the need for developers to handle Google Cloud credentials by letting Kubernetes controllers manage resources on their behalf through GitOps. But if KCC has broad organization-level IAM permissions, a user with limited Kubernetes access can exploit the confused deputy flaw in ConfigConfusion to gain Google Cloud control. #ConfigConnector #KCC #ConfigConfusion #WorkloadIdentity #GoogleKubernetesEngine
Keypoints
- KCC lets developers create Google Cloud resources through Kubernetes YAML without using cloud credentials.
- ConfigConfusion abuses KCC’s organization-level service account to escalate privileges.
- A user who can create IAMPolicyMember resources in a watched namespace can grant powerful IAM roles.
- The issue comes from two separate authorization systems that do not verify the full request together.
- Limiting KCC permissions and restricting IAM resource creation are key defenses.