This blog post explains the limitations of kube-linter in detecting privilege escalation in Kubernetes RBAC setups and introduces kube-chainsaw, a tool designed to analyze permission graphs from static manifests to identify and mitigate these security risks. It includes detailed instructions on installation, scanning manifests, and integrating the tool into CI pipelines while offering best practices for configuring RBAC.