kubectl auth can-i
SafeCheck RBAC permissions
kubectl auth can-i <verb> <resource>
Answers 'am I allowed?' before you try — and --as audits other identities. The Forbidden-error tool.
Examples
kubectl auth can-i delete pods -n prod --as system:serviceaccount:ci:deployerVerify a service account
Syntax
kubectl auth can-i <verb> <res> [--as user] [-n ns]
Before you run it
Check only.
Related commands
- kubectl describeDescribe resource/events
- kubectl get allEverything in a namespace
The same reference, with no signal at all
Every command and flow from this site, held on your device and searchable with no connection. Free to install, no ads.
Get it free on the App Store