Security researchers at Varonis have documented a confused deputy problem in Google Kubernetes Config Connector, a tool that lets Kubernetes deploy and manage GCP resources via YAML. According to the report highlighted by BleepingComputer, a Kubernetes user with limited native permissions can potentially abuse the service account that Config Connector uses, effectively turning a single YAML file into a lever for controlling an entire Google Cloud organization.
The core issue is that Config Connector is designed to translate YAML into cloud API calls, but it may not sufficiently validate whether the user requesting an action actually holds the corresponding GCP permission. This means a user who can create or modify certain Kubernetes resources—even ones that seem innocuous—might be able to trigger actions with the connector's elevated service account, bypassing intended separation of duties.
Varonis's research highlights how this can escalate from a minor Kubernetes namespace to full administrative control over GCP projects and, in some configurations, the whole organization. The report does not reveal a single bug fix, but rather points to a systemic risk in how such connectors are configured. The analysis underscores the need for careful alignment between Kubernetes RBAC and cloud IAM, and for treating any YAML that reaches Config Connector as potentially high-privilege code. This is based on a single source, so there are no differing accounts to compare.