DevOps Professional · Module 1: Platform design and tenancy · Lab
Fix Over-Permissive RBAC for Two Fictional Teams
50 min hands-on · Core
A local KinD or k3d cluster with two fictional team namespaces (team-a, team-b) starting from over-permissive bindings. Fictional tenants for practice; the RBAC machinery is real.
Local guide: run the steps below on your own machine in order, then check the validation list.
Objectives
- Narrow both teams to least-privilege namespace roles
- Prove the boundary with a negative check matrix
- Show legitimate work still flowing for both teams
Step 1
Record the over-permissive baseline
Document the starting bindings and demonstrate one cross-team action that currently succeeds (reading the other team's secret or deploying to its namespace). Quote the success as the fault evidence.
Step 2
Narrow to least privilege
Replace the broad bindings with namespace-scoped roles covering demonstrated needs only (deploy, roll back, read logs and config in the own namespace). Write the reason beside each granted verb.
Step 3
Run the negative matrix
As each team identity, attempt cross-team secret read, cross-team deploy and a cluster-admin verb; quote all denials. Then show each team's legitimate work succeeding and quote it.
How to confirm it worked
- Baseline fault quoted with a succeeding cross-team action
- Narrowed roles with per-verb reasons recorded
- Negative matrix quoted: cross-team actions denied
- Legitimate work for both teams quoted succeeding