Kubernetes RBAC rule with wildcard permissions

Replace unnecessary Kubernetes RBAC wildcards with specific permissions and review the scope of the role bindings.

Description

In Kubernetes RBAC, * in the apiGroups, resources, or verbs fields of a Role or ClusterRole covers every value in that field. These wildcards can grant more access than needed, depending on the other fields and bindings.

A * in one field does not automatically grant every operation on every resource across the cluster. Effective access depends on the other rule fields, the RoleBinding or ClusterRoleBinding, and the applicable namespace. Wildcards in resource or operation fields can also include targets added in the future.

Potential impact

  • Bound users or service accounts can receive unnecessary read, modify, or delete permissions.
  • A compromised account or workload can misuse permissions within the scope of its bindings.
  • Adding a new resource or operation can unintentionally expand access without any change to the role.

Remediation

  • Remove unnecessary * entries and list the required API groups, resources, and operations.
  • Confirm the role's purpose and inspect the subjects and scope of its RoleBinding and ClusterRoleBinding objects.
  • Check that the service account can still perform required operations and is denied unnecessary ones.

Examples

The examples compare wildcard permissions with explicitly listed operations. They also differ in role kind and namespace, so the second configuration should not directly replace the first. In an actual ClusterRole definition, omit metadata.namespace and determine the scope through bindings.

Role with wildcards

yaml
kind: Role
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  namespace: rbac2
  name: configmap-modifier
rules:
  - apiGroups: ["*"]
    resources: ["*"]
    verbs: ["*"]

ClusterRole with explicit operations

yaml
kind: ClusterRole
apiVersion: rbac.authorization.k8s.io/v1
metadata:
  namespace: opa
  name: configmap-modifier
rules:
  - apiGroups: [""]
    resources: ["configmaps"]
    verbs: ["update", "patch"]

Explanation:

  • Role with wildcards: apiGroups, resources, and verbs are all *. The permissions granted by this Role are still limited by the namespace of its binding.
  • ClusterRole with explicit operations: Only update and patch on configmaps in the core API group are listed. Verify that these permissions are needed. A ClusterRoleBinding can grant them across namespaces.

References