Role Dayalı Erişim Denetimi (RBAC)
Kubernetes kümenizde kullanıcı ve hizmet hesabı izinlerini güvenli bir şekilde yönetmek için RBAC'yi yapılandırın.
Role Dayalı Erişim Denetimi (RBAC), CoddyKit'te ücretsiz bir Docker & Kubernetes for Developers dersidir. Bu, 4 dersinin 1. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, Docker & Kubernetes for Developers öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. Docker & Kubernetes for Developers kursu toplamda 4 dersten oluşur.
Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.
What is Kubernetes RBAC?
Welcome to Role-Based Access Control (RBAC)! In Kubernetes, RBAC is a method for regulating access to computer or network resources based on the roles of individual users within your organization.
Think of it as the security guard for your cluster: it decides who can do what.
Why RBAC is Essential
RBAC is critical for cluster security and operational integrity. Without it, any user or process with access could potentially perform any action, leading to security vulnerabilities or accidental misconfigurations.
- Security: Prevents unauthorized access.
- Least Privilege: Ensures users/applications only have necessary permissions.
- Compliance: Helps meet regulatory requirements for access control.
RBAC Core Concepts: Subjects
In RBAC, a Subject is 'who' is performing an action. Kubernetes identifies three types of subjects:
- Users: Human users (often managed externally).
- Service Accounts: Identities for processes running in Pods. These are Kubernetes-native.
- Groups: Collections of Users or Service Accounts.
We'll focus on Service Accounts as they are central to application security within Kubernetes.
RBAC Core Concepts: Roles
A Role defines 'what' actions can be performed. Roles are always namespace-scoped, meaning the permissions they grant apply only within a specific namespace.
A Role contains rules, which are sets of permissions. Each rule specifies:
apiGroups: The API group the resource belongs to (e.g.,""for core,appsfor deployments).resources: The specific resource types (e.g.,pods,deployments).verbs: The actions allowed (e.g.,get,list,create,delete).
RBAC Core Concepts: ClusterRoles
Similar to Roles, a ClusterRole also defines 'what' actions can be performed, but it is cluster-scoped. This means its permissions apply across the entire cluster.
ClusterRoles are used for:
- Granting access to cluster-scoped resources (like nodes).
- Granting access to resources across all namespaces.
- Granting access to non-resource endpoints (like
/healthz).
RBAC Core Concepts: RoleBindings
A RoleBinding is 'how' permissions are granted. It links a Subject (User, ServiceAccount, or Group) to a Role.
Like Roles, RoleBindings are namespace-scoped. This means the binding grants the permissions defined in the Role to the Subject, but only within that specific namespace.
RBAC Core Concepts: ClusterRoleBindings
A ClusterRoleBinding links a Subject to a ClusterRole. Because ClusterRoles are cluster-scoped, a ClusterRoleBinding grants permissions across the entire cluster.
Use ClusterRoleBindings carefully, as they grant broad access. They are typically used for cluster administrators or system-level components.
Example: Creating a Service Account
Let's create a Service Account named my-app-sa in the default namespace. This Service Account will be the identity for a future application pod.
Run this command in your terminal:
kubectl create serviceaccount my-app-sa -n defaultExample: Defining a Pod Reader Role
Now, let's define a Role called pod-reader in the default namespace. This Role will allow subjects to get, list, and watch pods.
Save this YAML as pod-reader-role.yaml and apply it using kubectl apply -f pod-reader-role.yaml:
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: pod-reader
namespace: default
rules:
- apiGroups: [""] # Core API group
resources: ["pods", "pods/log"]
verbs: ["get", "list", "watch"]Example: Binding the Role
Finally, let's create a RoleBinding named read-pods-binding that links our my-app-sa Service Account to the pod-reader Role in the default namespace.
Save this YAML as pod-reader-binding.yaml and apply it:
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: read-pods-binding
namespace: default
subjects:
- kind: ServiceAccount
name: my-app-sa
namespace: default
roleRef:
kind: Role
name: pod-reader
apiGroup: rbac.authorization.k8s.ioQuick Check: RBAC Resources
Which Kubernetes resource is used to grant cluster-wide permissions to a Service Account?
RBAC: Key Takeaways
You've learned the fundamentals of Kubernetes RBAC!
- Subjects: Who is acting (Users, Service Accounts, Groups).
- Roles/ClusterRoles: What actions are allowed (namespace-scoped vs. cluster-scoped).
- RoleBindings/ClusterRoleBindings: How subjects are linked to permissions (namespace-scoped vs. cluster-scoped).
Mastering RBAC is crucial for securing your Kubernetes applications and infrastructure. Keep practicing with different permission sets!
Sıkça Sorulan Sorular
“Role Dayalı Erişim Denetimi (RBAC)” dersi ücretsiz mi?
Evet — “Role Dayalı Erişim Denetimi (RBAC)” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve Docker & Kubernetes for Developers kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. Docker & Kubernetes for Developers kursu toplamda 4 dersten oluşur.
“Role Dayalı Erişim Denetimi (RBAC)” dersinde ne öğreneceğim?
Kubernetes kümenizde kullanıcı ve hizmet hesabı izinlerini güvenli bir şekilde yönetmek için RBAC'yi yapılandırın. Docker & Kubernetes for Developers ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.
Docker & Kubernetes for Developers öğrenmeye başlamak için deneyim gerekli mi?
Önceden deneyim gerekmez. CoddyKit'te Docker & Kubernetes for Developers, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 1. dersidir.
“Role Dayalı Erişim Denetimi (RBAC)” dersi ne kadar sürer?
Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.
Bu Docker & Kubernetes for Developers dersinde kod yazıp çalıştırabilir miyim?
Evet. Her Docker & Kubernetes for Developers dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.
Bu kursun tüm dersleri
- Role Dayalı Erişim Denetimi (RBAC)
- Pod güvenliği ve imaj tarama
- Kubernetes ağ trafiğini güvenli hale getirme
- Harici Gizli Bilgi Depolarıyla Gizli Bilgileri Güvenle Yönetme