Description
RBAC manages user and service-account permissions through roles and bindings. A cluster using this authorization model must enable its RBAC authorizer. Supported versions can also configure it through AuthorizationConfiguration.
Enabling RBAC alone does not guarantee least privilege. Restrict roles and bindings to required actions and resources, and check that other authorization mechanisms do not allow unwanted requests.
Potential impact
- User and service-account permissions may be difficult to control precisely.
- Excessive access can expose sensitive resources.
- Permission audits and change management can become harder.
Remediation
- Enable RBAC through
--authorization-modeor AuthorizationConfiguration. - Commonly combine
RBAC,Nodeand review roles and bindings for least privilege. - Check static Pods and startup arguments for overly permissive authorization modes.
Examples
These are API server argument excerpts. Match the image to the actual cluster version. Other settings, including node authentication, roles and bindings, are omitted.
Before
yaml
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: registry.k8s.io/kube-apiserver:v1.34.0
command: ["kube-apiserver"]
args: ["--authorization-mode=AlwaysAllow"]
After
yaml
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: registry.k8s.io/kube-apiserver:v1.34.0
command: ["kube-apiserver"]
args: ["--authorization-mode=RBAC,Node"]
Explanation:
- Before: AlwaysAllow permits requests regardless of role permissions.
- After: RBAC is enabled. Check roles, bindings and other authorizers to determine the actual permission scope.