Kubernetes and Cloud Native Associate (KCNA)Kubernetes FundamentalsHard
A security engineer is reviewing the default access controls within a Kubernetes cluster. They want to understand how permissions for users and service accounts are defined and enforced across different resources and namespaces. Which Kubernetes authorization mechanism is primarily responsible for this?
- ANodeRestriction
- BRole-Based Access Control (RBAC)
- CPodSecurityPolicy
- DAdmission Controllers
Show answer & explanationAnswer & explanation
Correct answer: B. Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) is the primary authorization mechanism in Kubernetes. It allows cluster administrators to define roles with specific permissions (verbs on resources) and then bind those roles to users or service accounts, either cluster-wide or within specific namespaces.
Why the other options are wrong
- A. NodeRestriction is an admission controller that limits kubelet's API access to only objects it needs to manage, not general user permissions.
- C. PodSecurityPolicy (deprecated in favor of Pod Security Standards) focused on Pod-level security context, not general user/service account permissions.
- D. Admission Controllers intercept requests to the Kubernetes API server before persistence, but RBAC is the specific mechanism for defining permissions.
Role-Based Access Control (RBAC)
Role-Based Access Control (RBAC) is an authorization mechanism in Kubernetes that enables administrators to define permissions for users and service accounts by creating Roles and RoleBindings (or ClusterRoles and ClusterRoleBindings).
- Defines permissions (verbs on resources).
- Permissions granted via Roles (namespace-scoped) or ClusterRoles (cluster-scoped).
- Roles are bound to subjects (users, groups, service accounts) via RoleBindings/ClusterRoleBindings.
- Primary authorization mechanism in Kubernetes.
Memory trick: RBAC 'R'ules 'B'y 'A'llowing 'C'ontrol over resources.