Controllo degli accessi basato sui ruoli (RBAC)
Configuri RBAC per gestire in modo sicuro le autorizzazioni di utenti e account di servizio nel cluster Kubernetes.
Controllo degli accessi basato sui ruoli (RBAC) è una lezione Docker & Kubernetes for Developers gratuita su CoddyKit. Questa è la lezione 1 di 4. Puoi leggere la lezione completa qui gratuitamente — poi esercitati direttamente nel browser con un editor di codice integrato e un tutor IA disponibile 24/7. Fa parte del percorso di apprendimento Docker & Kubernetes for Developers, e i tuoi progressi si sincronizzano tra il web e l'app CoddyKit. Il corso Docker & Kubernetes for Developers include 4 lezioni in totale.
Parti di questa lezione non sono ancora state tradotte e vengono mostrate in inglese.
What is Kubernetes RBAC?
Welcome to Role-Based Access Control (RBAC)! In Kubernetes, RBAC is a method for regulating access to computer or network resources based on the roles of individual users within your organization.
Think of it as the security guard for your cluster: it decides who can do what.
Why RBAC is Essential
RBAC is critical for cluster security and operational integrity. Without it, any user or process with access could potentially perform any action, leading to security vulnerabilities or accidental misconfigurations.
- Security: Prevents unauthorized access.
- Least Privilege: Ensures users/applications only have necessary permissions.
- Compliance: Helps meet regulatory requirements for access control.
RBAC Core Concepts: Subjects
In RBAC, a Subject is 'who' is performing an action. Kubernetes identifies three types of subjects:
- Users: Human users (often managed externally).
- Service Accounts: Identities for processes running in Pods. These are Kubernetes-native.
- Groups: Collections of Users or Service Accounts.
We'll focus on Service Accounts as they are central to application security within Kubernetes.
RBAC Core Concepts: Roles
A Role defines 'what' actions can be performed. Roles are always namespace-scoped, meaning the permissions they grant apply only within a specific namespace.
A Role contains rules, which are sets of permissions. Each rule specifies:
apiGroups: The API group the resource belongs to (e.g.,""for core,appsfor deployments).resources: The specific resource types (e.g.,pods,deployments).verbs: The actions allowed (e.g.,get,list,create,delete).
RBAC Core Concepts: ClusterRoles
Similar to Roles, a ClusterRole also defines 'what' actions can be performed, but it is cluster-scoped. This means its permissions apply across the entire cluster.
ClusterRoles are used for:
- Granting access to cluster-scoped resources (like nodes).
- Granting access to resources across all namespaces.
- Granting access to non-resource endpoints (like
/healthz).
RBAC Core Concepts: RoleBindings
A RoleBinding is 'how' permissions are granted. It links a Subject (User, ServiceAccount, or Group) to a Role.
Like Roles, RoleBindings are namespace-scoped. This means the binding grants the permissions defined in the Role to the Subject, but only within that specific namespace.
RBAC Core Concepts: ClusterRoleBindings
A ClusterRoleBinding links a Subject to a ClusterRole. Because ClusterRoles are cluster-scoped, a ClusterRoleBinding grants permissions across the entire cluster.
Use ClusterRoleBindings carefully, as they grant broad access. They are typically used for cluster administrators or system-level components.
Example: Creating a Service Account
Let's create a Service Account named my-app-sa in the default namespace. This Service Account will be the identity for a future application pod.
Run this command in your terminal:
kubectl create serviceaccount my-app-sa -n defaultExample: Defining a Pod Reader Role
Now, let's define a Role called pod-reader in the default namespace. This Role will allow subjects to get, list, and watch pods.
Save this YAML as pod-reader-role.yaml and apply it using kubectl apply -f pod-reader-role.yaml:
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: pod-reader
namespace: default
rules:
- apiGroups: [""] # Core API group
resources: ["pods", "pods/log"]
verbs: ["get", "list", "watch"]Example: Binding the Role
Finally, let's create a RoleBinding named read-pods-binding that links our my-app-sa Service Account to the pod-reader Role in the default namespace.
Save this YAML as pod-reader-binding.yaml and apply it:
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: read-pods-binding
namespace: default
subjects:
- kind: ServiceAccount
name: my-app-sa
namespace: default
roleRef:
kind: Role
name: pod-reader
apiGroup: rbac.authorization.k8s.ioQuick Check: RBAC Resources
Which Kubernetes resource is used to grant cluster-wide permissions to a Service Account?
RBAC: Key Takeaways
You've learned the fundamentals of Kubernetes RBAC!
- Subjects: Who is acting (Users, Service Accounts, Groups).
- Roles/ClusterRoles: What actions are allowed (namespace-scoped vs. cluster-scoped).
- RoleBindings/ClusterRoleBindings: How subjects are linked to permissions (namespace-scoped vs. cluster-scoped).
Mastering RBAC is crucial for securing your Kubernetes applications and infrastructure. Keep practicing with different permission sets!
Impara Docker & Kubernetes for Developers con un tutor IA — gratis
Scrivi ed esegui vero codice nel tuo browser, ricevi aiuto istantaneo da un tutor IA disponibile 24/7, e riprendi da dove hai lasciato sul web o nell'app.
- Corsi
- 12
- Lezioni
- 48
Domande Frequenti
La lezione «Controllo degli accessi basato sui ruoli (RBAC)» è gratuita?
Sì — il testo completo di «Controllo degli accessi basato sui ruoli (RBAC)» è gratuito qui sul web. Per esercitarvi in modo interattivo (un editor di codice integrato e un tutor IA 24/7) e sbloccare il resto del corso Docker & Kubernetes for Developers, passa a CoddyKit PRO. Il corso Docker & Kubernetes for Developers include 4 lezioni in totale.
Cosa imparerò in «Controllo degli accessi basato sui ruoli (RBAC)»?
Configuri RBAC per gestire in modo sicuro le autorizzazioni di utenti e account di servizio nel cluster Kubernetes. Eserciti Docker & Kubernetes for Developers con codice pratico che esegui direttamente nel browser, e un tutor IA 24/7 risponde alle tue domande mentre lavori sulla lezione.
Ho bisogno di esperienza per iniziare Docker & Kubernetes for Developers?
Non è richiesta alcuna esperienza precedente. Docker & Kubernetes for Developers su CoddyKit è strutturato per principianti e studenti avanzati, quindi puoi iniziare da qui o dall'inizio e procedere al tuo ritmo. Questa è la lezione 1 di 4.
Quanto tempo richiede la lezione «Controllo degli accessi basato sui ruoli (RBAC)»?
La maggior parte delle lezioni CoddyKit richiede circa 5–10 minuti. Ogni lezione è breve e interattiva, quindi fai progressi costanti e riprendi esattamente da dove hai lasciato su web e app.
Posso scrivere ed eseguire codice in questa lezione Docker & Kubernetes for Developers?
Sì. Ogni lezione Docker & Kubernetes for Developers include un editor di codice integrato, quindi scrivi ed esegui codice reale direttamente nel tuo browser e ricevi feedback istantaneo dall'IA — nessuna configurazione locale necessaria.
Tutte le lezioni di questo corso
- Controllo degli accessi basato sui ruoli (RBAC)
- Sicurezza dei pod e scansione delle immagini
- Protezione del traffico di rete Kubernetes
- Gestire i Secrets in sicurezza con archivi esterni