Hands-on Lab·Certified Kubernetes Security Specialist
Minimizing an Over-Broad RBAC Role
The most likely RBAC task you will be handed is not writing a Role from nothing - it is taking one that says `*` and leaving it saying as little as possible. This guide does exactly that, and proves the result by testing what is still allowed and what is now refused.
Cluster Hardening Guide 9 of 40 Intermediate
- Kubernetesapiserver v1.36.4, kubelet v1.36.3
- Runtimecontainerd 2.2.6
- CNICilium 1.18.1 - tunnel/VXLAN, with Hubble relay and UI
- Host OSUbuntu 26.04 LTS, kernel 7.0.0-29
- Built withkubeadm v1.36.3 - podSubnet 10.244.0.0/16, serviceSubnet 10.96.0.0/12
- TimeAbout 18 min
- Reviewed25 August 2026
Written against the versions above. `kubectl create role --resource='*'` writes `apiGroups: [""]`, so its wildcard covers the core API group only. That is demonstrated here rather than assumed.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA6001 | 192.168.0.46 | Ubuntu 26.04 LTS | Control Plane Node (tainted NoSchedule) | 2 Core | 4 GB | 50 GB |
| CKA6001-NODE01 | 192.168.0.47 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA6001-NODE02 | 192.168.0.48 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 4 - the other half of exposure.
-
The grant you have been handed
-
What it can actually do
-
Decide what the workload needs, before writing anything
-
Replace it, and notice what had to be deleted
-
Prove it, in both directions