Review RBAC authorization settings

Review the RBAC authorizer with roles and bindings to enforce least privilege.

Description

RBAC manages user and service-account permissions through roles and bindings. A cluster using this authorization model must enable its RBAC authorizer. Supported versions can also configure it through AuthorizationConfiguration.

Enabling RBAC alone does not guarantee least privilege. Restrict roles and bindings to required actions and resources, and check that other authorization mechanisms do not allow unwanted requests.

Potential impact

  • User and service-account permissions may be difficult to control precisely.
  • Excessive access can expose sensitive resources.
  • Permission audits and change management can become harder.

Remediation

  • Enable RBAC through --authorization-mode or AuthorizationConfiguration.
  • Commonly combine RBAC,Node and review roles and bindings for least privilege.
  • Check static Pods and startup arguments for overly permissive authorization modes.

Examples

These are API server argument excerpts. Match the image to the actual cluster version. Other settings, including node authentication, roles and bindings, are omitted.

Before

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: registry.k8s.io/kube-apiserver:v1.34.0
      command: ["kube-apiserver"]
      args: ["--authorization-mode=AlwaysAllow"]

After

yaml
apiVersion: v1
kind: Pod
metadata:
  name: command-demo
spec:
  containers:
    - name: command-demo-container
      image: registry.k8s.io/kube-apiserver:v1.34.0
      command: ["kube-apiserver"]
      args: ["--authorization-mode=RBAC,Node"]

Explanation:

  • Before: AlwaysAllow permits requests regardless of role permissions.
  • After: RBAC is enabled. Check roles, bindings and other authorizers to determine the actual permission scope.

References