The most detailed free FDE + DevOps library: 140+ lessons, 70+ labs and 80 long-form articles, in English and Turkish. Start learning →

DevOps Professional · Module 1: Platform design and tenancy · Lab

Fix Over-Permissive RBAC for Two Fictional Teams

50 min hands-on · Core

A local KinD or k3d cluster with two fictional team namespaces (team-a, team-b) starting from over-permissive bindings. Fictional tenants for practice; the RBAC machinery is real.

Local guide: run the steps below on your own machine in order, then check the validation list.

Objectives

  • Narrow both teams to least-privilege namespace roles
  • Prove the boundary with a negative check matrix
  • Show legitimate work still flowing for both teams
  1. Step 1

    Record the over-permissive baseline

    Document the starting bindings and demonstrate one cross-team action that currently succeeds (reading the other team's secret or deploying to its namespace). Quote the success as the fault evidence.

  2. Step 2

    Narrow to least privilege

    Replace the broad bindings with namespace-scoped roles covering demonstrated needs only (deploy, roll back, read logs and config in the own namespace). Write the reason beside each granted verb.

  3. Step 3

    Run the negative matrix

    As each team identity, attempt cross-team secret read, cross-team deploy and a cluster-admin verb; quote all denials. Then show each team's legitimate work succeeding and quote it.

How to confirm it worked

  • Baseline fault quoted with a succeeding cross-team action
  • Narrowed roles with per-verb reasons recorded
  • Negative matrix quoted: cross-team actions denied
  • Legitimate work for both teams quoted succeeding