Name | Azure Kubernetes Service RBAC Reader | |||||||||||||||
Id | 7f6c6a51-bcf8-42ba-9220-52d62157d7db | |||||||||||||||
Description | Allows read-only access to see most objects in a namespace. It does not allow viewing roles or role bindings. This role does not allow viewing Secrets, since reading the contents of Secrets enables access to ServiceAccount credentials in the namespace, which would allow API access as any ServiceAccount in the namespace (a form of privilege escalation). Applying this role at cluster scope will give access across all namespaces. | |||||||||||||||
CreatedOn | 2020-07-02 17:53:05 UTC | |||||||||||||||
UpdatedOn | 2023-04-24 15:06:51 UTC | |||||||||||||||
History |
|
|||||||||||||||
Permissions summary | Effective control plane and data plane operations: 61 (unique operations) •read: 61 Actions: 4 Resolved control plane operations from Actions: 30 Effective control plane operations: 30 •read: 30 NotActions: 0 Resolved control plane operations from NotActions: 0 Effective denied control plane operations: 15770 DataActions: 31 Resolved data plane operations: 31 Effective data plane operations: 31 •read: 31 NotDataActions: 0 Resolved data plane operations from NotDataActions: 0 Effective denied data plane operations: 3152 |
|||||||||||||||
Actions |
|
|||||||||||||||
NotActions | n/a | |||||||||||||||
DataActions | ||||||||||||||||
NotDataActions | n/a | |||||||||||||||
Used in BuiltIn Policy |
none | |||||||||||||||
JSON |
|
|||||||||||||||
Condition | none |