Role-based access control (RBAC) decides what an authenticated identity may do. Permissions are always additive: there are no deny rules, so a user can do only what some role grants. Each rule lists API groups, resources and verbs such as get, list, watch, create, update, patch and delete.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.