alcideio/rbac-tool

who-can | add support for special RBAC verbs

gadinaor-r7 opened this issue · 0 comments

Per k8s rbac documentation there special cases

The following cases needs to be covered:

  1. 'bind' verb - see this
  2. 'escalate' - see this
  3. 'impersonate' verb see this

Reference: https://www.impidio.com/blog/kubernetes-rbac-security-pitfalls