Who may do what.
WHAT THE MODEL IS
Roles grant permissions; bindings attach roles to identities.
WHAT AN IDENTITY IS
A user, a group, or a service account used by workloads.
WHAT A ROLE COVERS
Permissions within one namespace.
WHAT A CLUSTER ROLE COVERS
The whole cluster.
WHAT TO GRANT
The minimum required.
WHY IT MATTERS ACUTELY
Broad permissions permit reading every secret in the cluster.
WHAT TO NEVER GRANT CASUALLY
Cluster administrator.
WHAT SERVICE ACCOUNTS ARE FOR
Workloads that need to call the cluster interface.
WHAT MOST WORKLOADS NEED
Nothing.
WHAT TO DO ABOUT THAT
Disable the automatic token mount where it is not needed.
WHY
A compromised container otherwise holds a credential to the cluster.
WHAT NAMESPACES PROVIDE
A boundary for permissions and quotas.
WHAT THEY DO NOT PROVIDE
Network isolation, by default.
WHAT TO ADD FOR THAT
Network policies.
WHAT A NETWORK POLICY DOES
Restricts which pods may communicate.
WHAT THE DEFAULT IS WITHOUT THEM
Everything can reach everything.
WHAT TO IMPLEMENT
Deny by default, permitting what is needed.
WHAT TO AUDIT
Who holds which roles, periodically.