Hands-on Lab·Certified Kubernetes Security Specialist
Auditing RBAC Permissions
Before you can minimise RBAC you have to find what is over-broad, and reading every Role by hand does not scale past about ten. This guide is six queries that answer the questions worth asking, all of them read-only, on a cluster you may not own.
Cluster Hardening Guide 10 of 40 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1
- Built withkubeadm v1.36.3
- TimeAbout 16 min
Every command here is read-only. Nothing is created, changed or deleted, which is what makes this safe to run during an assessment.
- Host kernel7.0.0-29
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA6001 | 192.168.0.46 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA6001-NODE01 | 192.168.0.47 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA6001-NODE02 | 192.168.0.48 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
This guide includes
Use this before minimising anything, because you cannot cut down what you have not found. This matters because reading every Role by hand does not scale - the audit is a set of queries, and every one of them is read-only.
- finding who holds cluster-admin, and which roles carry wildcards
- hunting the three verbs that turn a small grant into a large one - escalate, bind and impersonate
- establishing the floor: what every authenticated identity already has
- asking the two questions worth asking about any resource, as the identity rather than by reading YAML
- seeing how aggregated roles grow without anybody editing them
Before you start
- guide 9 - what you do with what this finds.
-
Who holds the keys
-
The three verbs that turn a small grant into a large one
-
What every authenticated identity already has
-
The two questions worth asking about any resource
-
The roles that grow without anyone editing them