RBAC là permission matrix
Thiết kế từ câu hỏi: ai (user/group/ServiceAccount) được verb nào trên resource/subresource ở scope nào. Ví dụ đọc Pod không tự cho đọc pods/log hoặc Secret; RoleBinding namespaced không giống ClusterRoleBinding.
Verify effective permission
Dùng identity đầy đủ và test allow/deny: auth can-i get pods, get pods/log, list secrets, update deployments, --all-namespaces khi phù hợp. Inspect binding và effective ClusterRole/aggregation; không suy luận quyền chỉ từ tên role. Sau khi revoke, chạy lại negative test và ghi evidence.
Bài tập
Tạo hai ServiceAccount với quyền khác nhau, hoàn thiện matrix, triển khai bindings, chạy positive/negative tests, tạo một lỗi scope/subresource rồi debug. Pass khi quyền tối thiểu đúng và revoke/cleanup không ảnh hưởng system RBAC.