Over-permissive RBAC: teams with keys to every room
Updated

Cluster-admin for everyone is a loan with interest: scope roles per team, review bindings quarterly, automate the audit.
Every cluster grows a drawer of all-powerful access: cluster-admin for the team that needed it once, wildcards from a copied example, bindings for people who left two years ago. Each is convenient until the incident where a typo or a token has no boundaries.
Scope, name, review
Scope roles to purpose. A deploy role writes deployments in named namespaces; a debug role reads logs and pods. Nothing human holds cluster-admin day to day.
Bind groups, not people. Team membership then drives access automatically. A person changing teams gains and loses exactly the right rooms.
Review on schedule. Quarterly, a named approver confirms each binding or it goes. Automation lists wildcards, dormant subjects and overly broad verbs between reviews.
Worked example: a fictional access audit
The context below is fictional. Fictional platform team ParcelOps (fictional) audits 60 bindings and finds 11 cluster-admin grants, 4 for departed staff, 9 wildcards from examples. One afternoon of owner interviews cuts admin to 2 break-glass bindings with alerts, scopes the rest per team, and schedules the quarterly review.
Next quarter: the review takes an hour, the automation flags two new wildcards, and no deployment breaks because nothing legitimate was removed.
Checklist: access with boundaries
- No human holds standing cluster-admin.
- Bindings target groups with scoped roles.
- Every binding has a named approver and a review date.
- Automation flags wildcards and dormant subjects.
Related reading
- Hands on: Over-Permissive RBAC in Teams.
- Professional level: DevOps Professional.
Straight answers
Frequently asked questions
Where do I start with messy RBAC?
List every binding that grants admin or cluster scope, then ask each owner what breaks without it. Most have no answer.
Roles per team or per person?
Per team and per purpose, bound to groups. Per-person bindings rot the day someone changes teams.
How do I keep it clean?
Quarterly reviews with named approvers plus automation that flags wildcards and dormant bindings.