OnCallReady

Commands

kubectl auth - Inspect authorization

kubectl auth can-i VERB [TYPE | TYPE/NAME | NONRESOURCEURL] [--as=USER] [--as-group=GROUP] [-n NS | -A] [--list] [--subresource=SUB] [-q]
kubectl auth whoami [--as=USER]

Options you will use

can-i VERB RESOURCE
yes/no (exit 0/1): does the apiserver let this identity do this? RESOURCE may be TYPE/NAME for resourceNames rules
--as=system:serviceaccount:NS:NAME
impersonate a ServiceAccount (or --as=jane for a user). This is THE way to debug "why is my app forbidden"
--as-group=GROUP
impersonate group membership too (repeatable)
--list
every rule that applies to the identity in the namespace (-n)
--subresource=log|exec|scale
check a subresource: kubectl auth can-i get pods --subresource=log
-A, --all-namespaces
check cluster-wide: only ClusterRoleBindings count
-q, --quiet
no output, only the exit code (for scripts)
whoami
who the apiserver thinks you are (Username + Groups)

Examples

$ kubectl auth can-i list pods -n dev --as=system:serviceaccount:dev:app

what the app's token may do

$ kubectl auth can-i --list -n dev --as=jane

everything jane can do in dev

$ kubectl auth can-i create pods/exec -n prod

can I exec into pods in prod?

$ kubectl auth can-i '*' '*'

am I cluster-admin?

Gotchas

Taught in

Try kubectl auth in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.