0Pricing
Docker & Kubernetes for Developers · Lesson

Role-Based Access Control (RBAC)

Configure RBAC to manage user and service account permissions within your Kubernetes cluster securely.

Role-Based Access Control (RBAC) is a free Docker & Kubernetes for Developers lesson on CoddyKit — lesson 1 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Docker & Kubernetes for Developers learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.

What is Kubernetes RBAC?

Welcome to Role-Based Access Control (RBAC)! In Kubernetes, RBAC is a method for regulating access to computer or network resources based on the roles of individual users within your organization.

Think of it as the security guard for your cluster: it decides who can do what.

Why RBAC is Essential

RBAC is critical for cluster security and operational integrity. Without it, any user or process with access could potentially perform any action, leading to security vulnerabilities or accidental misconfigurations.

  • Security: Prevents unauthorized access.
  • Least Privilege: Ensures users/applications only have necessary permissions.
  • Compliance: Helps meet regulatory requirements for access control.

RBAC Core Concepts: Subjects

In RBAC, a Subject is 'who' is performing an action. Kubernetes identifies three types of subjects:

  • Users: Human users (often managed externally).
  • Service Accounts: Identities for processes running in Pods. These are Kubernetes-native.
  • Groups: Collections of Users or Service Accounts.

We'll focus on Service Accounts as they are central to application security within Kubernetes.

RBAC Core Concepts: Roles

A Role defines 'what' actions can be performed. Roles are always namespace-scoped, meaning the permissions they grant apply only within a specific namespace.

A Role contains rules, which are sets of permissions. Each rule specifies:

  • apiGroups: The API group the resource belongs to (e.g., "" for core, apps for deployments).
  • resources: The specific resource types (e.g., pods, deployments).
  • verbs: The actions allowed (e.g., get, list, create, delete).

RBAC Core Concepts: ClusterRoles

Similar to Roles, a ClusterRole also defines 'what' actions can be performed, but it is cluster-scoped. This means its permissions apply across the entire cluster.

ClusterRoles are used for:

  • Granting access to cluster-scoped resources (like nodes).
  • Granting access to resources across all namespaces.
  • Granting access to non-resource endpoints (like /healthz).

RBAC Core Concepts: RoleBindings

A RoleBinding is 'how' permissions are granted. It links a Subject (User, ServiceAccount, or Group) to a Role.

Like Roles, RoleBindings are namespace-scoped. This means the binding grants the permissions defined in the Role to the Subject, but only within that specific namespace.

RBAC Core Concepts: ClusterRoleBindings

A ClusterRoleBinding links a Subject to a ClusterRole. Because ClusterRoles are cluster-scoped, a ClusterRoleBinding grants permissions across the entire cluster.

Use ClusterRoleBindings carefully, as they grant broad access. They are typically used for cluster administrators or system-level components.

Example: Creating a Service Account

Let's create a Service Account named my-app-sa in the default namespace. This Service Account will be the identity for a future application pod.

Run this command in your terminal:

kubectl create serviceaccount my-app-sa -n default

Example: Defining a Pod Reader Role

Now, let's define a Role called pod-reader in the default namespace. This Role will allow subjects to get, list, and watch pods.

Save this YAML as pod-reader-role.yaml and apply it using kubectl apply -f pod-reader-role.yaml:

apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: pod-reader
  namespace: default
rules:
- apiGroups: [""] # Core API group
  resources: ["pods", "pods/log"]
  verbs: ["get", "list", "watch"]

Example: Binding the Role

Finally, let's create a RoleBinding named read-pods-binding that links our my-app-sa Service Account to the pod-reader Role in the default namespace.

Save this YAML as pod-reader-binding.yaml and apply it:

apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
  name: read-pods-binding
  namespace: default
subjects:
- kind: ServiceAccount
  name: my-app-sa
  namespace: default
roleRef:
  kind: Role
  name: pod-reader
  apiGroup: rbac.authorization.k8s.io

Quick Check: RBAC Resources

Which Kubernetes resource is used to grant cluster-wide permissions to a Service Account?

RBAC: Key Takeaways

You've learned the fundamentals of Kubernetes RBAC!

  • Subjects: Who is acting (Users, Service Accounts, Groups).
  • Roles/ClusterRoles: What actions are allowed (namespace-scoped vs. cluster-scoped).
  • RoleBindings/ClusterRoleBindings: How subjects are linked to permissions (namespace-scoped vs. cluster-scoped).

Mastering RBAC is crucial for securing your Kubernetes applications and infrastructure. Keep practicing with different permission sets!

Frequently asked questions

Is the “Role-Based Access Control (RBAC)” lesson free?

Yes — the full text of “Role-Based Access Control (RBAC)” is free to read here on the web, and the Docker & Kubernetes for Developers course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Docker & Kubernetes for Developers course, upgrade to CoddyKit PRO.

What will I learn in “Role-Based Access Control (RBAC)”?

Configure RBAC to manage user and service account permissions within your Kubernetes cluster securely. You practise Docker & Kubernetes for Developers with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.

Do I need any experience to start Docker & Kubernetes for Developers?

No prior experience is required. Docker & Kubernetes for Developers on CoddyKit is structured for beginners through advanced learners; this is — lesson 1 of 4, so you can start here or from the beginning and move at your own pace.

How long does the “Role-Based Access Control (RBAC)” lesson take?

Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.

Can I write and run code in this Docker & Kubernetes for Developers lesson?

Yes. Every Docker & Kubernetes for Developers lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.

All lessons in this course

  1. Role-Based Access Control (RBAC)
  2. Pod Security & Image Scanning
  3. Securing Kubernetes Network Traffic
  4. Managing Secrets Securely with External Secret Stores
← Back to Docker & Kubernetes for Developers