
RBAC done properly: roles, bindings and least privilege
Role-based access control decays unless it is maintained. How permissions, roles and bindings fit together, and how to find roles nobody holds or that grant nothing.
2 posts

Role-based access control decays unless it is maintained. How permissions, roles and bindings fit together, and how to find roles nobody holds or that grant nothing.

A shared kubeconfig tells the cluster nothing about who is calling. How OIDC, RBAC subjects and short-lived credentials tie Kubernetes access to a person or workload.