Role vs. ClusterRole
CONCEPTS:Role-Based Access Control (RBAC)
Question Variations
- "What is the difference between a `Role` and a `ClusterRole` in Kubernetes RBAC?"
- "When would you use a `ClusterRoleBinding` instead of a `RoleBinding`?"
- "Can you use a `RoleBinding` to grant permissions defined in a `ClusterRole`? Why would you do this?"
- "Explain the purpose of a `ServiceAccount` and how it interacts with RBAC."
Why This Is Asked
Security is a top priority in Kubernetes. This question tests whether a candidate understands how to isolate permissions and follow the principle of least privilege. Knowing when to use namespace-scoped vs. cluster-scoped permissions is fundamental to cluster security.
Key Concepts
- Namespacing: How Roles are restricted to a single namespace.
- Aggregation: How ClusterRoles can be used to grant permissions across all namespaces.
- ServiceAccounts: The primary way applications authenticate with the API.
- Binding: The link between the permission (Role) and the identity (Subject).
Question Variations
- “What is the difference between a
Roleand aClusterRolein Kubernetes RBAC?” - “When would you use a
ClusterRoleBindinginstead of aRoleBinding?” - “Can you use a
RoleBindingto grant permissions defined in aClusterRole? Why would you do this?” - “Explain the purpose of a
ServiceAccountand how it interacts with RBAC.”