List of Kubernetes RBAC rule verbs
2022-12-26
# 要了解正在运行的集群上 apiGroups 和资源的完整谓词列表,包括随运算符或 CRD 引入的任何其他谓词,您可以执行以下操作。
kubectl proxy
# List all API urls
curl http://localhost:8001/ | yq '.paths[]'
# List all objects and verbs for an API path like /api/v1
curl http://localhost:8001/api/v1 | yq '.resources[] | [{"resources":.name,"verbs":.verbs}]'
(base) ~/ k get clusterrole kube-eventer -o yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:
name: kube-eventer
rules:
- apiGroups:
- ""
resources:
- events
verbs:
- get
- list
- watch