RBAC (Role-Based Access Control)
RBAC decides who may do what in Kubernetes. A Role lists allowed verbs on resources in a namespace, a ClusterRole does it cluster-wide, and a RoleBinding or ClusterRoleBinding gives it to a user, group or ServiceAccount. Everything is denied unless a rule allows it.
Key concepts #
- Verbs:
get,list,watch,create,update,patch,delete. - ServiceAccount: the identity of a pod.
- Built-in roles:
view,edit,admin,cluster-admin. - Check:
kubectl auth can-i.
Learn it #
Follow Namespaces and RBAC.