René's URL Explorer Experiment


Title: Authorize actions in clusters using role-based access control  |  GKE security  |  Google Cloud Documentation

Open Graph Title: Authorize actions in clusters using role-based access control  |  GKE security  |  Google Cloud Documentation

Description: Authorize actions in clusters using role-based access control (RBAC) in Kubernetes.

Open Graph Description: Authorize actions in clusters using role-based access control (RBAC) in Kubernetes.

Opengraph URL: https://docs.cloud.google.com/kubernetes-engine/docs/how-to/role-based-access-control

direct link

Domain: cloud.google.com


Hey, it has json ld scripts:
  {
    "@context": "https://schema.org",
    "@type": "Article",
    
    "headline": "Authorize actions in clusters using role-based access control"
  }
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "itemListElement": [{
      "@type": "ListItem",
      "position": 1,
      "name": "Google Kubernetes Engine (GKE)",
      "item": "https://docs.cloud.google.com/kubernetes-engine/docs"
    },{
      "@type": "ListItem",
      "position": 2,
      "name": "GKE security",
      "item": "https://docs.cloud.google.com/kubernetes-engine/docs/concepts/security-overview"
    },{
      "@type": "ListItem",
      "position": 3,
      "name": "Authorize actions in clusters using role-based access control",
      "item": "https://docs.cloud.google.com/kubernetes-engine/docs/how-to/role-based-access-control"
    }]
  }
  

google-signin-client-id721724668570-nbkv1cfusk7kk4eni4pjvepaus73b13t.apps.googleusercontent.com
google-signin-scopeprofile email https://www.googleapis.com/auth/developerprofiles https://www.googleapis.com/auth/developerprofiles.award https://www.googleapis.com/auth/devprofiles.full_control.firstparty
og:site_nameGoogle Cloud Documentation
og:typewebsite
theme-color#1a73e8
NoneIE=Edge
og:imagehttps://docs.cloud.google.com/_static/cloud/images/social-icon-google-cloud-1200-630.png
og:image:width1200
og:image:height630
og:localeen
twitter:cardsummary_large_image

Links:

Skip to main content https://cloud.google.com/kubernetes-engine/docs/how-to/role-based-access-control#main-content
https://cloud.google.com/
Technology areas https://docs.cloud.google.com/docs
AI and ML https://docs.cloud.google.com/docs/ai-ml
Application development https://docs.cloud.google.com/docs/application-development
Application hosting https://docs.cloud.google.com/docs/application-hosting
Compute https://docs.cloud.google.com/docs/compute-area
Data analytics and pipelines https://docs.cloud.google.com/docs/data
Databases https://docs.cloud.google.com/docs/databases
Distributed, hybrid, and multicloud https://docs.cloud.google.com/docs/dhm-cloud
Industry solutions https://docs.cloud.google.com/docs/industry
Migration https://docs.cloud.google.com/docs/migration
Networking https://docs.cloud.google.com/docs/networking
Observability and monitoring https://docs.cloud.google.com/docs/observability
Security https://docs.cloud.google.com/docs/security
Storage https://docs.cloud.google.com/docs/storage
Cross-product tools https://docs.cloud.google.com/docs/cross-product-overviews
Access and resources management https://docs.cloud.google.com/docs/access-resources
Costs and usage management https://docs.cloud.google.com/docs/costs-usage
Infrastructure as code https://docs.cloud.google.com/docs/iac
SDK, languages, frameworks, and tools https://docs.cloud.google.com/docs/devtools
Console https://console.cloud.google.com/
https://docs.cloud.google.com/kubernetes-engine/docs/concepts/security-overview
Google Kubernetes Engine (GKE) https://docs.cloud.google.com/kubernetes-engine/docs
GKE security https://docs.cloud.google.com/kubernetes-engine/docs/concepts/security-overview
Start freehttps://console.cloud.google.com/freetrial
Overview https://docs.cloud.google.com/kubernetes-engine/docs
Guides https://docs.cloud.google.com/kubernetes-engine/docs/concepts/security-overview
https://cloud.google.com/
Technology areas https://cloud.google.com/docs
Overview https://cloud.google.com/kubernetes-engine/docs
Guides https://cloud.google.com/kubernetes-engine/docs/concepts/security-overview
Cross-product tools https://cloud.google.com/docs/cross-product-overviews
Console https://console.cloud.google.com/
GKE security overviewhttps://cloud.google.com/kubernetes-engine/docs/concepts/security-overview
Overviewhttps://cloud.google.com/kubernetes-engine/security/explore-gke-docs
Main GKE documentationhttps://cloud.google.com/kubernetes-engine/docs/concepts/kubernetes-engine-overview
GKE AI/ML documentationhttps://cloud.google.com/kubernetes-engine/docs/concepts/machine-learning
GKE networking documentationhttps://cloud.google.com/kubernetes-engine/docs/concepts/explore-gke-networking-docs-use-cases
GKE security documentationhttps://cloud.google.com/kubernetes-engine/docs/concepts/security-overview
GKE fleet management documentationhttps://cloud.google.com/kubernetes-engine/fleet-management/docs
Security measures in GKE Autopilothttps://cloud.google.com/kubernetes-engine/docs/concepts/autopilot-security
About cluster trusthttps://cloud.google.com/kubernetes-engine/docs/concepts/cluster-trust
Shared security responsibilitieshttps://cloud.google.com/kubernetes-engine/docs/concepts/shared-responsibility
Authenticate to the GKE APIhttps://cloud.google.com/kubernetes-engine/docs/authentication
Authenticate to the Kubernetes API serverhttps://cloud.google.com/kubernetes-engine/docs/how-to/api-server-authentication
Use external identity providers to authenticate to GKE clustershttps://cloud.google.com/kubernetes-engine/docs/how-to/oidc
About service accounts in GKEhttps://cloud.google.com/kubernetes-engine/docs/how-to/service-accounts
Configure GKE node service accountshttps://cloud.google.com/kubernetes-engine/security/configure-node-service-accounts
About RBAC and IAMhttps://cloud.google.com/kubernetes-engine/docs/concepts/access-control
Best practices for RBAChttps://cloud.google.com/kubernetes-engine/docs/best-practices/rbac
Authorize access to Google Cloud resources using IAM policieshttps://cloud.google.com/kubernetes-engine/docs/how-to/iam
Authorize actions in clusters using GKE RBAChttps://cloud.google.com/kubernetes-engine/docs/how-to/role-based-access-control
Manage permissions for groups using Google Groups with RBAChttps://cloud.google.com/kubernetes-engine/docs/how-to/google-groups-rbac
Enable access and view cluster resources by namespacehttps://cloud.google.com/kubernetes-engine/docs/how-to/restrict-resources-access-by-namespace
Access scopes in GKEhttps://cloud.google.com/kubernetes-engine/docs/how-to/access-scopes
About Workload Identity Federation for GKEhttps://cloud.google.com/kubernetes-engine/docs/concepts/workload-identity
Authenticate to Google Cloud APIs from GKEhttps://cloud.google.com/kubernetes-engine/docs/how-to/workload-identity
Access secrets stored outside GKE clusters using client librarieshttps://cloud.google.com/kubernetes-engine/docs/tutorials/workload-identity-secrets
Access private registries with private CA certificateshttps://cloud.google.com/kubernetes-engine/docs/how-to/access-private-registries-private-certificates
Harden your clustershttps://cloud.google.com/kubernetes-engine/docs/how-to/hardening-your-cluster
Security patchinghttps://cloud.google.com/kubernetes-engine/docs/resources/security-patching
Mitigate security incidentshttps://cloud.google.com/kubernetes-engine/docs/how-to/security-mitigations
Disable the insecure kubelet read-only porthttps://cloud.google.com/kubernetes-engine/docs/how-to/disable-kubelet-readonly-port
Run VM agents on every GKE nodehttps://cloud.google.com/kubernetes-engine/docs/how-to/enforce-vm-agents
Manage node SSH access without using SSH keyshttps://cloud.google.com/kubernetes-engine/docs/how-to/enable-oslogin
Securely load modules on nodes running COShttps://cloud.google.com/kubernetes-engine/security/secure-modules-cos
About GKE Sandboxhttps://cloud.google.com/kubernetes-engine/docs/concepts/sandbox-pods
Isolate your workloads using GKE Sandboxhttps://cloud.google.com/kubernetes-engine/docs/how-to/sandbox-pods
Isolate your workloads in dedicated node poolshttps://cloud.google.com/kubernetes-engine/docs/how-to/isolate-workloads-dedicated-nodes
About seccomp in GKEhttps://cloud.google.com/kubernetes-engine/docs/concepts/seccomp-in-gke
Isolate your workloads using sole-tenant nodeshttps://cloud.google.com/kubernetes-engine/docs/how-to/sole-tenancy
Configure workload separation in GKEhttps://cloud.google.com/kubernetes-engine/docs/how-to/workload-separation
Rotate your cluster's credentialshttps://cloud.google.com/kubernetes-engine/docs/how-to/credential-rotation
Rotate your control plane IP addresseshttps://cloud.google.com/kubernetes-engine/docs/how-to/ip-rotation
About FIPS-validated encryption in GKEhttps://cloud.google.com/kubernetes-engine/docs/concepts/gke-fips-compliance
Encrypt your data in-use with GKE Confidential Nodeshttps://cloud.google.com/kubernetes-engine/docs/how-to/confidential-gke-nodes
Encrypt your data in-transit in GKE with user-managed encryption keyshttps://cloud.google.com/kubernetes-engine/docs/how-to/enable-inter-node-transparent-encryption
Encrypt data at rest with keys that you managehttps://cloud.google.com/kubernetes-engine/docs/how-to/using-cmek
Encrypt Secrets at the application layerhttps://cloud.google.com/kubernetes-engine/docs/how-to/encrypting-secrets
vTPM in Confidential GKE workloadshttps://cloud.google.com/kubernetes-engine/docs/how-to/vtpms
Apply predefined Pod-level security policies using PodSecurityhttps://cloud.google.com/kubernetes-engine/docs/how-to/podsecurityadmission
Apply custom Pod-level security policies using Gatekeeperhttps://cloud.google.com/kubernetes-engine/docs/how-to/pod-security-policies-with-gatekeeper
Restrict actions on GKE resources using custom organization policieshttps://cloud.google.com/kubernetes-engine/docs/how-to/custom-org-policies
Selectively enforce firewall policies in GKEhttps://cloud.google.com/kubernetes-engine/docs/how-to/tags-firewall-policies
Use network tags to apply firewall rules to nodeshttps://cloud.google.com/kubernetes-engine/docs/how-to/autopilot-network-tags
About control plane securityhttps://cloud.google.com/kubernetes-engine/docs/concepts/control-plane-security
About cluster trusthttps://cloud.google.com/kubernetes-engine/docs/concepts/cluster-trust
About control plane authorityhttps://cloud.google.com/kubernetes-engine/docs/concepts/about-control-plane-authority
Run your own certificate authorities and keys in GKEhttps://cloud.google.com/kubernetes-engine/docs/tutorials/run-your-own-cas-keys
Encrypt etcd and control plane boot diskshttps://cloud.google.com/kubernetes-engine/docs/how-to/encrypt-etcd-control-plane-disks
Rotate customer-managed control plane CAs and keyshttps://cloud.google.com/kubernetes-engine/docs/how-to/rotate-control-plane-cas-keys
Rotate etcd and control plane boot disk encryption keyshttps://cloud.google.com/kubernetes-engine/docs/how-to/rotate-etcd-kcp-encryption-keys
Verify Google connections to the GKE control planehttps://cloud.google.com/kubernetes-engine/docs/how-to/verify-google-connections-control-plane
Verify identity issuance and usagehttps://cloud.google.com/kubernetes-engine/docs/how-to/verify-identity-issuance-usage
Verify GKE control plane VM integrityhttps://cloud.google.com/kubernetes-engine/docs/how-to/verify-control-plane-vm-integrity
Audit logging for Kuberneteshttps://cloud.google.com/kubernetes-engine/docs/how-to/audit-logging
Audit logging for Kubernetes Enginehttps://cloud.google.com/kubernetes-engine/docs/how-to/audit-logging-container
Audit logging for Container Security APIhttps://cloud.google.com/kubernetes-engine/docs/how-to/audit-logging-container-security
About audit policyhttps://cloud.google.com/kubernetes-engine/docs/concepts/audit-policy
Enable Linux auditd logging in Standard clustershttps://cloud.google.com/kubernetes-engine/docs/how-to/linux-auditd-logging
About the security posture dashboardhttps://cloud.google.com/kubernetes-engine/docs/concepts/about-security-posture-dashboard
About Kubernetes security posture scanninghttps://cloud.google.com/kubernetes-engine/docs/concepts/about-configuration-scanning
Scan workloads for configuration issueshttps://cloud.google.com/kubernetes-engine/docs/how-to/protect-workload-configuration
About workload vulnerability scanninghttps://cloud.google.com/kubernetes-engine/docs/concepts/about-workload-vulnerability-scanning
Scan containers for known vulnerabilitieshttps://cloud.google.com/kubernetes-engine/docs/how-to/security-posture-vulnerability-scanning
Configure GKE security posture features for fleetshttps://cloud.google.com/kubernetes-engine/docs/how-to/fleet-security-posture
Authenticationhttps://cloud.google.com/kubernetes-engine/docs/troubleshooting/authentication
Service accountshttps://cloud.google.com/kubernetes-engine/docs/troubleshooting/service-accounts
Application-layer secrets encryptionhttps://cloud.google.com/kubernetes-engine/docs/troubleshooting/troubleshoot-secrets
CRDs with an invalid CA bundlehttps://cloud.google.com/kubernetes-engine/docs/how-to/crd-with-invalid-caBundle
AI and ML https://cloud.google.com/docs/ai-ml
Application development https://cloud.google.com/docs/application-development
Application hosting https://cloud.google.com/docs/application-hosting
Compute https://cloud.google.com/docs/compute-area
Data analytics and pipelines https://cloud.google.com/docs/data
Databases https://cloud.google.com/docs/databases
Distributed, hybrid, and multicloud https://cloud.google.com/docs/dhm-cloud
Industry solutions https://cloud.google.com/docs/industry
Migration https://cloud.google.com/docs/migration
Networking https://cloud.google.com/docs/networking
Observability and monitoring https://cloud.google.com/docs/observability
Security https://cloud.google.com/docs/security
Storage https://cloud.google.com/docs/storage
Access and resources management https://cloud.google.com/docs/access-resources
Costs and usage management https://cloud.google.com/docs/costs-usage
Infrastructure as code https://cloud.google.com/docs/iac
SDK, languages, frameworks, and tools https://cloud.google.com/docs/devtools
Home https://docs.cloud.google.com/
Documentation https://docs.cloud.google.com/docs
Application hosting https://docs.cloud.google.com/docs/application-hosting
Google Kubernetes Engine (GKE) https://docs.cloud.google.com/kubernetes-engine/docs
GKE security https://docs.cloud.google.com/kubernetes-engine/docs/concepts/security-overview
Autopilot https://cloud.google.com/kubernetes-engine/docs/concepts/autopilot-overview
Standard https://cloud.google.com/kubernetes-engine/docs/concepts/choose-cluster-mode
Common GKE user roles and taskshttps://cloud.google.com/kubernetes-engine/enterprise/docs/concepts/roles-tasks
Overview of Kubernetes RBAChttps://kubernetes.io/docs/reference/access-authn-authz/rbac/
Best practices for GKE RBAChttps://cloud.google.com/kubernetes-engine/docs/best-practices/rbac
Enable Google Kubernetes Engine API https://console.cloud.google.com/flows/enableapi?apiid=container.googleapis.com
installhttps://cloud.google.com/sdk/docs/install
initializehttps://cloud.google.com/sdk/docs/initializing
propertyhttps://cloud.google.com/sdk/docs/properties#setting_properties
Identity and Access Management (IAM)https://cloud.google.com/kubernetes-engine/docs/how-to/iam
configure the kubectl command to authenticate to Google Cloudhttps://cloud.google.com/kubernetes-engine/docs/how-to/cluster-access-for-kubectl
Cluster access for kubectlhttps://cloud.google.com/kubernetes-engine/docs/how-to/cluster-access-for-kubectl#authentication
Rolehttps://kubernetes.io/docs/reference/kubernetes-api/authorization-resources/role-v1/
ClusterRolehttps://kubernetes.io/docs/reference/kubernetes-api/authorization-resources/cluster-role-v1/
cluster-admin IAM rolehttps://cloud.google.com/iam/docs/roles-permissions/container
Configure Google Groups for RBAChttps://cloud.google.com/kubernetes-engine/docs/how-to/google-groups-rbac
pod-reader Rolehttps://cloud.google.com/kubernetes-engine/docs/how-to/role-based-access-control#role
Identity and Access Management (IAM)https://cloud.google.com/kubernetes-engine/docs/how-to/iam
Verifying API Accesshttps://kubernetes.io/docs/reference/access-authn-authz/authorization/#checking-api-access
Using Role-Based Access Control Authorizationhttps://kubernetes.io/docs/reference/access-authn-authz/rbac/
Admin activity audit loghttps://cloud.google.com/kubernetes-engine/docs/how-to/audit-logging
default ClusterRoles and ClusterRoleBindingshttps://kubernetes.io/docs/reference/access-authn-authz/rbac/#discovery-roles
CustomResourceDefinitionshttps://kubernetes.io/docs/concepts/extend-kubernetes/api-extension/custom-resources/#customresourcedefinitions
configure Google Groups for RBAChttps://cloud.google.com/kubernetes-engine/docs/how-to/google-groups-rbac
create IAM allow policieshttps://cloud.google.com/kubernetes-engine/docs/how-to/iam
access controlhttps://cloud.google.com/kubernetes-engine/docs/concepts/access-control
best practices for GKE RBAChttps://cloud.google.com/kubernetes-engine/docs/best-practices/rbac
authenticate to the Kubernetes API serverhttps://cloud.google.com/kubernetes-engine/docs/how-to/api-server-authentication
Creative Commons Attribution 4.0 Licensehttps://creativecommons.org/licenses/by/4.0/
Apache 2.0 Licensehttps://www.apache.org/licenses/LICENSE-2.0
Google Developers Site Policieshttps://developers.google.com/site-policies
See all products https://cloud.google.com/products/
Google Cloud pricing https://cloud.google.com/pricing/
Google Cloud Marketplace https://cloud.google.com/marketplace/
Contact sales https://cloud.google.com/contact/
Community forums https://discuss.google.dev/c/google-cloud/14/
Support https://cloud.google.com/support-hub/
Release Notes https://docs.cloud.google.com/release-notes
System status https://status.cloud.google.com
GitHub https://github.com/googlecloudPlatform/
Getting Started with Google Cloud https://cloud.google.com/docs/get-started/
Code samples https://cloud.google.com/docs/samples
Cloud Architecture Center https://cloud.google.com/architecture/
Training and Certification https://cloud.google.com/learn/training/
Blog https://cloud.google.com/blog/
Events https://cloud.google.com/events/
X (Twitter) https://x.com/googlecloud
Google Cloud on YouTube https://www.youtube.com/googlecloud
Google Cloud Tech on YouTube https://www.youtube.com/googlecloudplatform
About Google https://about.google/
Privacy https://policies.google.com/privacy
Site terms https://policies.google.com/terms?hl=en
Google Cloud terms https://cloud.google.com/product-terms
Manage cookies https://cloud.google.com/kubernetes-engine/docs/how-to/role-based-access-control
Our third decade of climate action: join us https://cloud.google.com/sustainability
Subscribe https://cloud.google.com/newsletter/

Viewport: width=device-width, initial-scale=1


URLs of crawlers that visited me.