kubectl auth - Inspect authorization
kubectl auth can-i VERB [TYPE | TYPE/NAME | NONRESOURCEURL] [--as=USER] [--as-group=GROUP] [-n NS | -A] [--list] [--subresource=SUB] [-q]
kubectl auth whoami [--as=USER]
Options you will use
can-i VERB RESOURCE- yes/no (exit 0/1): does the apiserver let this identity do this? RESOURCE may be TYPE/NAME for resourceNames rules
--as=system:serviceaccount:NS:NAME- impersonate a ServiceAccount (or --as=jane for a user). This is THE way to debug "why is my app forbidden"
--as-group=GROUP- impersonate group membership too (repeatable)
--list- every rule that applies to the identity in the namespace (-n)
--subresource=log|exec|scale- check a subresource: kubectl auth can-i get pods --subresource=log
-A, --all-namespaces- check cluster-wide: only ClusterRoleBindings count
-q, --quiet- no output, only the exit code (for scripts)
whoami- who the apiserver thinks you are (Username + Groups)
Examples
$ kubectl auth can-i list pods -n dev --as=system:serviceaccount:dev:appwhat the app's token may do
$ kubectl auth can-i --list -n dev --as=janeeverything jane can do in dev
$ kubectl auth can-i create pods/exec -n prodcan I exec into pods in prod?
$ kubectl auth can-i '*' '*'am I cluster-admin?
Gotchas
- RBAC is additive: there are no deny rules, so can-i answers "is there ANY binding that grants this".
- kubectl auth can-i get pods/log checks a pod NAMED "log" - use --subresource=log.
Taught in
Try kubectl auth in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.