Marcus Noble 1/20/2022

Restricting cluster-admin Permissions

Read Original

This technical article discusses a limitation of Kubernetes RBAC, which only allows adding permissions. It details a real-world problem where a buggy CLI tool used by cluster-admins was causing issues, and explains how the team at Giant Swarm used the Kyverno admission controller to create a ClusterPolicy that blocks specific delete actions, effectively restricting permissions even for users with the cluster-admin role.

Restricting cluster-admin Permissions

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

1
The Beautiful Web
Jens Oliver Meiert 2 votes
3
LLM Use in the Python Source Code
Miguel Grinberg 1 votes
4
Wagon’s algorithm in Python
John D. Cook 1 votes