Kubernetes pentest: come un token rubato in un Pod porta, via RBAC e nodes/proxy, a privilege escalation e shell root sul nodo, con kubectl e cheatsheet.