RBAC & Permissions
KubeBolt auto-detects your kubeconfig's permissions and adapts automatically.
This page is about what KubeBolt may do in the cluster. What each KubeBolt user may do in KubeBolt — the Viewer, Editor and Admin roles — is covered in Authentication. An action needs both: a role that allows it and cluster permissions that allow it.
Permission Detection
- Uses
SelfSubjectAccessReviewAPI to testlistverb for 31 resource types - Two-phase: cluster-wide first, then namespace-level fallback for RoleBinding-based access
- Concurrent execution (semaphore of 10), completes in ~2-5 seconds
- If SSAR API itself is unavailable, falls back to assume full access
Access Levels
| Level | Backend | Frontend |
|---|---|---|
| Cluster-admin | All informers start normally | Full UI, no restrictions |
| Cluster read-only | Informers for permitted resources only | Restricted items dimmed, “Limited access” banner |
| Namespace-scoped | Per-namespace informer factories with multi-lister aggregation | Resources scoped to permitted namespaces |
Frontend Behavior
- “Limited access — showing X of Y resource types” banner
- Sidebar items dimmed with shield icon for restricted resources
- Summary cards show “No access” instead of “0”
- “No access to Nodes — capacity data unavailable” for node restrictions
PermissionDeniedcomponent for 403 resource pages
The agent’s RBAC tiers
Everything above describes the kubeconfig path, where KubeBolt probes the
permissions it was handed. On agent-connected clusters
you choose the scope up front instead, with --set rbac.mode= on the agent
chart:
metrics— narrow ClusterRole: kubelet stats, pods list/watch, namespaces get. The agent ships metrics and Hubble flows and nothing else; no apiserver call traverses its tunnel. Impliesproxy.enabled=false.reader(default) — cluster-wideget/list/watchon*/*. The backend reads inventory through the agent’s tunnel for a full read-only dashboard; write verbs come back 403. Impliesproxy.enabled=true.operator— read and write on*/*, effectively cluster-admin scoped to the agent’s ServiceAccount. Required for exec, scale, restart, delete and YAML edits through the dashboard. Requiresauth.mode != "disabled".
API Endpoint
GET /api/v1/cluster/permissions returns the full permission map per resource type with canList, canWatch, canGet, namespaceScoped, and namespaces fields.