Kubernetes Security Operations: Difference between revisions
Jump to navigation
Jump to search
Line 1: | Line 1: | ||
=Internal= | =Internal= | ||
* [[Kubernetes Operations]] | * [[Kubernetes Operations]] | ||
* [[rbac-lookup]] | |||
=Service Account Operations= | =Service Account Operations= |
Revision as of 20:39, 4 September 2020
Internal
Service Account Operations
RBAC Operations
Authorization Check
PodSecurityPolicy
This command allows to simulate the PodSecurityPolicy selection process performed by the PodSecurityPolicy admission controller:
kubectl --as=system:serviceaccount:<namespace>:<serviceaccount-name> -n <namespace> auth can-i use <pod-security-policy-name>
kubectl --as=system:serviceaccount:blue:blue-serviceaccount -n blue auth can-i use podsecuritypolicy/example