Kubernetes RBAC

Cluster permissions compose in ways that are easy to grant and hard to reason about afterwards.

Roles, cluster roles, bindings, service accounts and aggregation combine, and the effective answer is frequently broader than anybody intended. Certain permissions are also equivalent to administrator in disguise, such as anything that can create workloads or read secrets across the cluster.

Checked against the primary source.

More on Containers & Kubernetes