Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium
A platform team is configuring Role-Based Access Control (RBAC) for a new developer team in a Kubernetes cluster. The developers need to be able to deploy new Pods, view logs of their own Pods, and update Deployments within their designated namespace. However, they should NOT be able to delete namespaces or modify cluster-wide resources. Which RBAC resource type should the platform team primarily use to define these permissions, and then bind them to the developer's ServiceAccounts or Users?
- AClusterRole and ClusterRoleBinding
- BSecurityContext and PodSecurityPolicy
- CServiceAccount and User
- DRole and RoleBinding
Show answer & explanationAnswer & explanation
Correct answer: D. Role and RoleBinding
Roles and RoleBindings are used to define and apply permissions *within a specific namespace*. Since the developer team's permissions are restricted to their 'designated namespace' and they should 'NOT be able to delete namespaces or modify cluster-wide resources', a Role (defining the permissions) and a RoleBinding (assigning the Role to users/service accounts within that namespace) are the appropriate RBAC resources.
Why the other options are wrong
- A. ClusterRole and ClusterRoleBinding define permissions across the entire cluster, which goes against the requirement to prevent modification of 'cluster-wide resources'.
- B. SecurityContext and PodSecurityPolicy (now deprecated in favor of PSA) define Pod-level security settings, not access control for Kubernetes API resources.
- C. ServiceAccount and User are subjects to which permissions are granted, not the resources that define the permissions themselves.
Kubernetes Role (RBAC)
An RBAC resource in Kubernetes that defines a set of permissions (verbs on resources) within a specific namespace, used to grant access to users, groups, or ServiceAccounts.
- Namespace-scoped: permissions apply only within a single namespace.
- Defines allowed actions (verbs) on specific resources (e.g., 'get', 'list', 'create' on 'pods').
- Bound to subjects using a RoleBinding.
Memory trick: Roles for namespaces, ClusterRoles for clusters.