# RBAC (Role-Based Access Control)

> RBAC in Kubernetes grants permissions to users, groups and service accounts with Roles and ClusterRoles bound by RoleBindings and ClusterRoleBindings.

- Source: https://www.itwonderlab.com/rbac/
- Published: 2026-09-14
- Updated: 2026-09-14
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

**RBAC** decides who may do what in [Kubernetes](https://www.itwonderlab.com/kubernetes/). A **Role** lists allowed verbs on resources in a namespace, a **ClusterRole** does it cluster-wide, and a **RoleBinding** or **ClusterRoleBinding** gives it to a user, group or ServiceAccount. Everything is denied unless a rule allows it.

### Key concepts

- **Verbs**: `get`, `list`, `watch`, `create`, `update`, `patch`, `delete`.
- **ServiceAccount**: the identity of a pod.
- **Built-in roles**: `view`, `edit`, `admin`, `cluster-admin`.
- **Check**: `kubectl auth can-i`.

### Learn it

Follow [Namespaces and RBAC](https://www.itwonderlab.com/kubernetes-namespaces-rbac/).
