Hands-on Lab·Certified Kubernetes Administrator
Troubleshooting Authentication and Authorization Failures
Four ways a request fails to reach an object, produced deliberately one after another, so the error text tells you which layer to look at instead of sending you to RBAC every time.
Troubleshooting Guide 103 of 103 Intermediate
- Kubernetes1.36.4
- Runtimecontainerd 2.2.6
- CNICalico v3.32.1
- TimeAbout 17 min
- Reviewed26 August 2026
Written against the versions above. The ServiceAccount token here is created with a 30 minute lifetime. Nothing on this page changes cluster configuration.
| Server Name | IP Address | OS | Roles | CPU | RAM | HDD |
|---|---|---|---|---|---|---|
| CKA1001 | 192.168.0.175 | Ubuntu 26.04 LTS | Control Plane Node | 2 Core | 4 GB | 50 GB |
| CKA1001-NODE01 | 192.168.0.176 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA1001-NODE02 | 192.168.0.177 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
| CKA1001-NODE03 | 192.168.0.178 | Ubuntu 26.04 LTS | Worker Node | 2 Core | 4 GB | 50 GB |
Before you start
- guide 15 - what a 403 means, before this covers the failures that are not one.
-
Who you are right now
-
Build a second identity and use it
-
The same request with a broken token
-
The same request with the wrong CA
-
The failure with no error message