Skip to content
EgyKode
06 · KubernetesLab 39 / 59
Guided labkubernetes

Kubernetes RBAC & Service Accounts

Grant a namespace read-only access, give a workload its own identity, and verify with the cluster rather than by hoping.

Time
50 min
Level
Intermediate
Objectives
4 objectives
Cost
Free

Where this fits in the platform

This lab adds

  • Workload identities that can do only what they need

Before you start

You will need

  • kind or minikube
  • kubectl 1.28+

You do not need these already — the lab environment below provides them.

You will be able to

  • Assemble Role, RoleBinding, ClusterRole and ClusterRoleBinding correctly
  • Give a Pod an identity that is not the default ServiceAccount
  • Verify permissions with `auth can-i` instead of by trial

CostFree

— kind or minikube.

Nothing to pay in the browser. Open the terminal runs this against a simulated cloud — the same API calls and the same commands, with no account and no bill. The figure above applies only if you build it in your own.

How to clean up

The scenario#

Every workload in the cluster runs as the default ServiceAccount, and its token is mounted into every Pod. Anything that reaches a container reaches the Kubernetes API with it.

NetworkPolicies control what a Pod can talk to. RBAC controls what it can do, and you need both.

Hands-on environment

Run this lab in a real terminal, free and in your browser. The environment is temporary and yours alone — break it as much as you like.

Open the terminal

Opens in Killercoda, in a new tab — keep this page open for the steps.

Run it on your own machine

Run this lab on your own machine. One command starts the environment, with everything the lab needs already installed:

You will need:

  • docker
  • kubectl
  • kind
git clone https://github.com/EgyKode/EgyKode-lab.git
cd EgyKode-lab
./egykode start k8s
./egykode shell

You need Docker and Git installed. Everything else runs inside the environment. The first start downloads it and takes a few minutes; later starts are seconds.

Not sure what you already have? Run: npm run doctor — it checks and changes nothing.

Anything you tick here is your own record. EgyKode cannot see inside that terminal, so the success criteria stay self-assessed even when the environment checks your work for you.

Four objects, two questions

Step 1 of 7

Clean up#

Run this even if you did not finish.

DestructiveThis removes real resources. Check which environment you are in first.

Terminal
kubectl delete namespace <ns> --ignore-not-found
kubectl get all -A | grep -v kube-system

Cost of this lab: Free — kind or minikube.

Success criteria

0 of 4

The concept behind it

Ready to try it without help?Do the challenge

Next up

Lab 39 of 59 on the project path

Kubernetes Security Hardening (NetworkPolicies) & HPADeny traffic between Pods by default, then allow only what the application needs — and scale it under load.Why next: Workload identities that can do only what they need47 minIntermediate

Previous: From Ingress to Gateway API