RBAC là permission graph
Đọc subject → binding → role → apiGroup/resource/verb → scope. Role/RoleBinding thường giới hạn namespace; ClusterRole/ClusterRoleBinding có thể mở rộng rất lớn. ServiceAccount là identity của workload, không phải lý do để nhúng token vào image.
Verify effective access
Dùng auth can-i để test allowed/denied path, kể cả namespace và subresource. Một Role tên “reader” vẫn có thể sai nếu verb/resource quá rộng. Sau thay đổi, inspect binding và test lại; cleanup phải revoke binding trước khi xóa identity.
Bài tập
Tạo reader Role/Binding, test ConfigMap allow và Secret/delete deny, sau đó mô phỏng revoke. Ghi permission matrix, expected can-i output và cleanup. Pass khi không cần cluster-admin để hoàn thành task.