Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsEasy
A security engineer is reviewing the default access controls within a Kubernetes cluster. They want to understand how permissions are granted to users and ServiceAccounts for interacting with Kubernetes API resources. Which mechanism is used for this purpose?
- AAdmission Controllers
- BPod Security Standards (PSS)
- CRole-Based Access Control (RBAC)
- DNetworkPolicy
Show answer & explanationAnswer & explanation
Correct answer: C. Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) is the primary mechanism in Kubernetes for regulating access to Kubernetes API resources based on the roles of individual users and ServiceAccounts. It defines permissions (verbs) on resources (nouns) and binds them to subjects.
Why the other options are wrong
- A. Admission Controllers intercept requests to the Kubernetes API server before persistence of the object, often enforcing policies, but RBAC is the mechanism for defining *who* can make *what* requests.
- B. Pod Security Standards (PSS) define security best practices for Pods but do not manage API access.
- D. NetworkPolicy controls network traffic flow between Pods, not access to the Kubernetes API.
Role-Based Access Control (RBAC)
A method of regulating access to Kubernetes API resources based on the roles of individual users and ServiceAccounts, defining permissions on specific resources.
- Controls access to Kubernetes API.
- Uses Roles/ClusterRoles and RoleBindings/ClusterRoleBindings.
- Applies to users and ServiceAccounts.
Memory trick: RBAC: Roles Bind Access Control!