Description
In Kubernetes RBAC, * in the apiGroups, resources, or verbs fields of a Role or ClusterRole covers every value in that field. These wildcards can grant more access than needed, depending on the other fields and bindings.
A * in one field does not automatically grant every operation on every resource across the cluster. Effective access depends on the other rule fields, the RoleBinding or ClusterRoleBinding, and the applicable namespace. Wildcards in resource or operation fields can also include targets added in the future.
Potential impact
- Bound users or service accounts can receive unnecessary read, modify, or delete permissions.
- A compromised account or workload can misuse permissions within the scope of its bindings.
- Adding a new resource or operation can unintentionally expand access without any change to the role.
Remediation
- Remove unnecessary
*entries and list the required API groups, resources, and operations. - Confirm the role's purpose and inspect the subjects and scope of its
RoleBindingandClusterRoleBindingobjects. - Check that the service account can still perform required operations and is denied unnecessary ones.
Examples
The examples compare wildcard permissions with explicitly listed operations. They also differ in role kind and namespace, so the second configuration should not directly replace the first. In an actual ClusterRole definition, omit metadata.namespace and determine the scope through bindings.
Role with wildcards
kind: Role
apiVersion: rbac.authorization.k8s.io/v1
metadata:
namespace: rbac2
name: configmap-modifier
rules:
- apiGroups: ["*"]
resources: ["*"]
verbs: ["*"]
ClusterRole with explicit operations
kind: ClusterRole
apiVersion: rbac.authorization.k8s.io/v1
metadata:
namespace: opa
name: configmap-modifier
rules:
- apiGroups: [""]
resources: ["configmaps"]
verbs: ["update", "patch"]
Explanation:
- Role with wildcards:
apiGroups,resources, andverbsare all*. The permissions granted by thisRoleare still limited by the namespace of its binding. - ClusterRole with explicit operations: Only
updateandpatchonconfigmapsin the core API group are listed. Verify that these permissions are needed. AClusterRoleBindingcan grant them across namespaces.