KubeBolt docs
GitHub

RBAC & Permissions

KubeBolt auto-detects your kubeconfig's permissions and adapts automatically.

This page is about what KubeBolt may do in the cluster. What each KubeBolt user may do in KubeBolt — the Viewer, Editor and Admin roles — is covered in Authentication. An action needs both: a role that allows it and cluster permissions that allow it.

Permission Detection

Access Levels

LevelBackendFrontend
Cluster-adminAll informers start normallyFull UI, no restrictions
Cluster read-onlyInformers for permitted resources onlyRestricted items dimmed, “Limited access” banner
Namespace-scopedPer-namespace informer factories with multi-lister aggregationResources scoped to permitted namespaces

Frontend Behavior

The agent’s RBAC tiers

Everything above describes the kubeconfig path, where KubeBolt probes the permissions it was handed. On agent-connected clusters you choose the scope up front instead, with --set rbac.mode= on the agent chart:

API Endpoint

GET /api/v1/cluster/permissions returns the full permission map per resource type with canList, canWatch, canGet, namespaceScoped, and namespaces fields.