- Home
- All questions
- Question 596
CKA study material · question 596 of 1000
A namespace administrator who cannot list Secrets cluster-wide tries to create a ClusterRole granting that permission. What happens?
Show the answer
Answer: A. The request is forbidden unless they hold the escalate verb on clusterroles
A subject may only create or update a role granting permissions they already hold at the same scope, unless they have been explicitly granted the escalate verb.
Source: Using RBAC Authorization (Kubernetes) — Privilege escalation prevention and bootstrapping › Restrictions on role creation or update