Kubernetes RBAC

Tricks and Caveats

Nicholas Dille, Haufe Group

DevOps Meetup


  • RBAC is well documented in the ecosystem
  • Little known verbs are a risk
  • Impersonation can improve security
  • Service account tokens must be managed
  • Policy management - e.g. Kyverno - for the rescue

