Role-Based Access Control (RBAC) grants permissions through two kinds of objects: roles, which list what actions are allowed, and bindings, which give those roles to users, groups or ServiceAccounts. Permissions are only ever added; there is no way to write a deny rule.
Free account
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.