Skip to content

Conversation

@ibihim
Copy link
Collaborator

@ibihim ibihim commented Oct 10, 2025

What

Shows how you can safely give full CRUD RBAC to fake resource.

Why

To show that you don't need to bind the RBAC of a user to a real k8s resource and indirectly alllowing that user to do CRUD on that resource.

E.g. malicious user of upstream, with kube-rbac-proxy configured to check user/post RBAC against resource X specified in ResourceAttributes, can create unlimited amount of resource X

@ibihim ibihim closed this Nov 21, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant