logo

Kubernetes RBAC: Asking for Forgiveness or Getting Permission

ID: 11526b2f-7d6f-5c31-8cfc-ff313245d590

STIX ID: report--11526b2f-7d6f-5c31-8cfc-ff313245d590

Feed Name: Aqua Security Blog

Date Published: 2019-06-03

Date Updated: 2026-04-26

...
...

This blog post explains Kubernetes RBAC, contrasts it with Linux permissions, and warns that RBAC configurations tend to become overly permissive over time. It advocates enforcing least-privilege, demonstrates how to check permissions (including using `kubectl auth can-i`), and introduces the `who-can` kubectl plugin to help identify which identities can perform specific actions, urging administrators to tighten permissions to reduce compromise risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.