ContainerCluster

Cluster control plane (ECS cluster/AKS/GKE/EKS).

class: Compute

Realizing resources

aws aws

resourcescopeenumeraterequired permissions
aws:ecs:cluster regional ecs:ListClusters ecs:ListClusters

azure azure

resourcescopeenumeraterequired permissions
azure:servicefabric:cluster global arg:microsoft.servicefabric/clusters Microsoft.ServiceFabric/clusters/read

Exposure sites

None.

Rules that touch ContainerCluster 7

Modify an ADF Integration Runtime configuration to swap SHIR VM assignment, reconfigure managed VNet, or change IR type - enables command execution or data exfiltration via network steering.
Node-level code execution (privileged pod, hostPID, DaemonSet exec) reaches the node IMDS and mints a token for the node system-assigned / kubelet MI.
managedClusters/agentPools/write + assign on a target MI allows swapping the kubelet MI, binding all nodes to a more-privileged identity.
Submit a job to an AKS cluster attached as an AML compute target; the job runs inside the AKS cluster as a Kubernetes workload, enabling lateral movement to non-AML K8s resources.
Modify a pool startTask/config + the pool runs as an MI => execute as that MI (via IMDS).
Submit a data-plane task + the pool runs as an MI => execute as that MI (via IMDS).
The Cloud Deploy execution SA's GKE deployment permissions (container.developer) give it CanDeploy to a GKE cluster.
move · open · esc close