RBAC (Role-Based Access Control)

· 1 min read · Containers and Orchestration · Concept

RBAC decides who may do what in Kubernetes. A Role lists allowed verbs on resources in a namespace, a ClusterRole does it cluster-wide, and a RoleBinding or ClusterRoleBinding gives it to a user, group or ServiceAccount. Everything is denied unless a rule allows it.

Key concepts #

  • Verbs: get, list, watch, create, update, patch, delete.
  • ServiceAccount: the identity of a pod.
  • Built-in roles: view, edit, admin, cluster-admin.
  • Check: kubectl auth can-i.

Learn it #

Follow Namespaces and RBAC.

More tutorials that use RBAC (Role-Based Access Control)

#Kubernetes