Study. uk . com
  1. Home
  2. All questions
  3. Question 611

CKA study material · question 611 of 1000

A Role grants list and watch on secrets in a namespace, intending to cover only the Secrets a controller's Pods use. What does it actually grant?

  1. Only the Secrets referenced by that controller's Pods
  2. Metadata for all Secrets, but not their values
  3. The contents of every Secret in that namespace
  4. Nothing, since list and watch require resourceNames
Show the answer

Answer: C. The contents of every Secret in that namespace

list and watch on Secrets return the data of all of them in the namespace, not just the ones a subject's Pods reference, which is why the verbs are worth granting narrowly.

Source: Secrets (Kubernetes) — Information security for Secrets

Challenge yourself on this topic → Study as cards