{"id":1477,"date":"2025-06-02T06:16:33","date_gmt":"2025-06-01T21:16:33","guid":{"rendered":"https:\/\/itstudy365.com\/blog\/?p=1477"},"modified":"2025-06-02T06:16:33","modified_gmt":"2025-06-01T21:16:33","slug":"kubernetes-learning-%e7%ac%ac29%e7%ab%a0%ef%bc%9arbac%e3%81%ae%e5%9f%ba%e7%a4%8e%e3%81%a8%e3%83%ad%e3%83%bc%e3%83%ab%e8%a8%ad%e8%a8%88-%e3%80%9c%e3%80%8c%e8%aa%b0%e3%81%8c%e3%80%81%e4%bd%95%e3%82%92","status":"publish","type":"post","link":"https:\/\/itstudy365.com\/blog\/2025\/06\/02\/kubernetes-learning-%e7%ac%ac29%e7%ab%a0%ef%bc%9arbac%e3%81%ae%e5%9f%ba%e7%a4%8e%e3%81%a8%e3%83%ad%e3%83%bc%e3%83%ab%e8%a8%ad%e8%a8%88-%e3%80%9c%e3%80%8c%e8%aa%b0%e3%81%8c%e3%80%81%e4%bd%95%e3%82%92\/","title":{"rendered":"Kubernetes Learning \u7b2c29\u7ae0\uff1aRBAC\u306e\u57fa\u790e\u3068\u30ed\u30fc\u30eb\u8a2d\u8a08 \u301c\u300c\u8ab0\u304c\u3001\u4f55\u3092\u3001\u3069\u3053\u3067\u300d\u3067\u304d\u308b\u306e\u304b\u3092\u5236\u5fa1\u3059\u308b\u301c"},"content":{"rendered":"\n<button id=\"bb1\" type=\"button\" value=\"Play\" class=\"responsivevoice-button\" title=\"ResponsiveVoice Tap to Start\/Stop Speech\"><span>&#128266; Play<\/span><\/button>\n        <script>\n            bb1.onclick = function(){\n                if(responsiveVoice.isPlaying()){\n                    responsiveVoice.cancel();\n                }else{\n                    responsiveVoice.speak(\"Kubernetes\u3067\u306f\u3001\u30af\u30e9\u30b9\u30bf\u306e\u30ea\u30bd\u30fc\u30b9\u306b\u5bfe\u3059\u308b\u30a2\u30af\u30bb\u30b9\u5236\u5fa1\u3092\u884c\u3046\u4ed5\u7d44\u307f\u3068\u3057\u3066 RBAC\uff08Role-Based Access Control\uff09 \u304c\u7528\u610f\u3055\u308c\u3066\u3044\u307e\u3059\u3002\u3053\u308c\u306f\u6587\u5b57\u901a\u308a\u300c\u30ed\u30fc\u30eb\u306b\u57fa\u3065\u3044\u305f\u30a2\u30af\u30bb\u30b9\u5236\u5fa1\u300d\u3067\u3001\u300c\u8ab0\u304c\u300d\u300c\u4f55\u3092\u300d\u300c\u3069\u3053\u3067\u300d\u3067\u304d\u308b\u306e\u304b \u3092\u660e\u78ba\u306b\u8a2d\u5b9a\u3067\u304d\u307e\u3059\u3002 \u2705 \u306a\u305cRBAC\u304c\u5fc5\u8981\u306a\u306e\uff1f Kubernetes\u30af\u30e9\u30b9\u30bf\u30fc\u3067\u306f\u3001\u591a\u304f\u306e\u30ea\u30bd\u30fc\u30b9\uff08Pod\u3001Service\u3001Secret\u306a\u3069\uff09\u3068\u3001\u591a\u304f\u306e\u30e6\u30fc\u30b6\u30fc\uff08\u958b\u767a\u8005\u3001CI\/CD\u30c4\u30fc\u30eb\u3001\u7ba1\u7406\u8005\u306a\u3069\uff09\u304c\u5b58\u5728\u3057\u307e\u3059\u3002\u305d\u306e\u305f\u3081\u3001\u5168\u54e1\u306b\u30d5\u30eb\u30a2\u30af\u30bb\u30b9\u3092\u8a31\u3057\u3066\u3057\u307e\u3046\u3068\u4e8b\u6545\u3084\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30ea\u30b9\u30af\u304c\u5897\u5927\u3057\u307e\u3059\u3002 RBAC\u3092\u4f7f\u3046\u3053\u3068\u3067\uff1a \u7279\u5b9a\u306e\u30e6\u30fc\u30b6\u30fc\u306b\u300cPod\u306e\u53c2\u7167\u3060\u3051\u8a31\u53ef\u300d\u306a\u3069\u306e\u5236\u9650\u304c\u3067\u304d\u308b \u30c1\u30fc\u30e0\u3054\u3068\u306b\u30a2\u30af\u30bb\u30b9\u7bc4\u56f2\u3092\u5206\u96e2\u3067\u304d\u308b \u6700\u5c0f\u6a29\u9650\u306e\u539f\u5247\uff08\u5fc5\u8981\u306a\u6a29\u9650\u3060\u3051\u4e0e\u3048\u308b\uff09\u3092\u5b9f\u73fe\u3067\u304d\u308b \ud83e\udde9 RBAC\u306e\u57fa\u672c\u69cb\u6210 RBAC\u3067\u306f\u4e3b\u306b\u4ee5\u4e0b\u306e4\u3064\u306e\u30ea\u30bd\u30fc\u30b9\u304c\u767b\u5834\u3057\u307e\u3059\uff1a \u30ea\u30bd\u30fc\u30b9\u5f79\u5272Role \/ ClusterRole\u3069\u3093\u306a\u64cd\u4f5c\u3092\u8a31\u53ef\u3059\u308b\u304b\uff08\u4f8b: Pod\u306e\u53d6\u5f97\uff09RoleBinding \/ ClusterRoleBinding\u8ab0\u306b\u305d\u306e\u30ed\u30fc\u30eb\u3092\u5272\u308a\u5f53\u3066\u308b\u304b \u7c21\u5358\u306b\u8a00\u3046\u3068\uff1a Role \u306f Namespace\u5358\u4f4d \u306e\u6a29\u9650 ClusterRole \u306f \u30af\u30e9\u30b9\u30bf\u5168\u4f53 \u306b\u307e\u305f\u304c\u308b\u6a29\u9650 RoleBinding \/ ClusterRoleBinding \u3067 \u30e6\u30fc\u30b6\u30fc\uff08\u307e\u305f\u306fServiceAccount\uff09\u306b\u30ed\u30fc\u30eb\u3092\u7d10\u3065\u3051\u307e\u3059 \ud83e\uddea \u4f8b\uff1a\u7279\u5b9aNamespace\u5185\u3067Pod\u306e\u4e00\u89a7\u53d6\u5f97\u3060\u3051\u8a31\u53ef\u3059\u308b # Role\u306e\u5b9a\u7fa9 apiVersion: rbac.authorization.k8s.io\/v1 kind: Role metadata: namespace: dev-team name: pod-reader rules: - apiGroups: [\\\"\\\"] resources: [\\\"pods\\\"] verbs: [\\\"get\\\", \\\"list\\\"] # RoleBinding\u306e\u5b9a\u7fa9 apiVersion: rbac.authorization.k8s.io\/v1 kind: RoleBinding metadata: name: read-pods-binding namespace: dev-team subjects: - kind: User name: \\\"alice\\\" apiGroup: rbac.authorization.k8s.io roleRef: kind: Role name: pod-reader apiGroup: rbac.authorization.k8s.io \u3053\u306e\u4f8b\u3067\u306f\uff1a alice \u3068\u3044\u3046\u30e6\u30fc\u30b6\u30fc\u306f dev-team \u540d\u524d\u7a7a\u9593\u306e Pod \u306b\u5bfe\u3057\u3066 get \/ list \u304c\u3067\u304d\u307e\u3059 \u4ed6\u306e\u30ea\u30bd\u30fc\u30b9\uff08Secret\u306a\u3069\uff09\u3084\u4ed6\u306eNamespace\u306b\u306f\u30a2\u30af\u30bb\u30b9\u3067\u304d\u307e\u305b\u3093 \ud83d\udee1 \u30ed\u30fc\u30eb\u8a2d\u8a08\u306e\u30dd\u30a4\u30f3\u30c8 \u6700\u5c0f\u6a29\u9650\u306e\u539f\u5247\u3092\u610f\u8b58\u3059\u308b\u2192 \u5fc5\u8981\u6700\u5c0f\u9650\u306e verbs\u30fbresources \u3092\u8a31\u53ef Namespace\u3054\u3068\u306e\u5206\u96e2\u2192 \u30c1\u30fc\u30e0\u3054\u3068\u306b Role\/RoleBinding \u3092\u5206\u3051\u308b\u3068\u7ba1\u7406\u3057\u3084\u3059\u3044 ClusterRole \u306f\u614e\u91cd\u306b\u2192 ClusterRole \u306f\u5f37\u529b\u306a\u306e\u3067\u3001\u57fa\u672c\u7684\u306b\u306f\u7ba1\u7406\u8005\u3084CI\/CD\u306b\u9650\u5b9a\u3059\u308b ServiceAccount \u306b\u30d0\u30a4\u30f3\u30c9\u3059\u308b\u3053\u3068\u3067\u3001\u30a2\u30d7\u30ea\u306b\u6a29\u9650\u3092\u4e0e\u3048\u308b\u2192 \u4eba\u3060\u3051\u3067\u306a\u304f\u3001\u30a2\u30d7\u30ea\uff08Pod\uff09\u306b\u3082\u8a8d\u8a3c\u30fb\u8a8d\u53ef\u304c\u5fc5\u8981\u306a\u5834\u9762\u3067\u4f7f\u3046 \ud83d\udca1 \u3088\u304f\u3042\u308b\u30e6\u30fc\u30b9\u30b1\u30fc\u30b9 \u30e6\u30fc\u30b9\u30b1\u30fc\u30b9\u4f7f\u7528\u3059\u308b\u30ea\u30bd\u30fc\u30b9\u30c1\u30fc\u30e0\u3054\u3068\u306b Namespace \u5185\u30ea\u30bd\u30fc\u30b9\u3092\u64cd\u4f5c\u53ef\u80fd\u306b\u3059\u308bRole + RoleBindingCI\/CD\u30c4\u30fc\u30eb\u306b\u30af\u30e9\u30b9\u30bf\u5168\u4f53\u306e\u30c7\u30d7\u30ed\u30a4\u6a29\u9650\u3092\u4e0e\u3048\u308bClusterRole + ClusterRoleBindingPod \u306b\u8aad\u307f\u53d6\u308a\u5c02\u7528\u306eSecret\u30a2\u30af\u30bb\u30b9\u3092\u8a31\u53efRole + RoleBinding \u3092 ServiceAccount \u306b\u7d10\u4ed8\u3051 \ud83d\udccc RBAC\u8a2d\u5b9a\u306e\u78ba\u8a8d\u65b9\u6cd5 # \u3042\u308b\u30e6\u30fc\u30b6\u30fc\u304c Pod \u306e get \u6a29\u9650\u3092\u6301\u3063\u3066\u3044\u308b\u304b\u78ba\u8a8d kubectl auth can-i get pods --as alice --namespace dev-team \ud83d\udd1a \u307e\u3068\u3081 RBAC\u306fKubernetes\u306b\u304a\u3051\u308b\u30a2\u30af\u30bb\u30b9\u5236\u5fa1\u306e\u4e2d\u6838\u3067\u3042\u308a\u3001\u5b89\u5168\u306a\u904b\u7528\u306b\u306f\u6b20\u304b\u305b\u307e\u305b\u3093\u3002 \u30ed\u30fc\u30eb\uff08Role \/ ClusterRole\uff09\u3067\u300c\u4f55\u304c\u3067\u304d\u308b\u304b\u300d\u3092\u5b9a\u7fa9\u3057\u3001 \u30d0\u30a4\u30f3\u30c7\u30a3\u30f3\u30b0\uff08RoleBinding \/ ClusterRoleBinding\uff09\u3067\u300c\u8ab0\u304c\u4f7f\u3046\u304b\u300d\u3092\u7d10\u3065\u3051\u307e\u3059\u3002\", \"Japanese Female\");\n                }\n            };\n        <\/script>\n    <\/p>\n\n\n\n<p>Kubernetes\u3067\u306f\u3001\u30af\u30e9\u30b9\u30bf\u306e\u30ea\u30bd\u30fc\u30b9\u306b\u5bfe\u3059\u308b\u30a2\u30af\u30bb\u30b9\u5236\u5fa1\u3092\u884c\u3046\u4ed5\u7d44\u307f\u3068\u3057\u3066 <strong>RBAC\uff08Role-Based Access Control\uff09<\/strong> \u304c\u7528\u610f\u3055\u308c\u3066\u3044\u307e\u3059\u3002<br>\u3053\u308c\u306f\u6587\u5b57\u901a\u308a\u300c\u30ed\u30fc\u30eb\u306b\u57fa\u3065\u3044\u305f\u30a2\u30af\u30bb\u30b9\u5236\u5fa1\u300d\u3067\u3001<strong>\u300c\u8ab0\u304c\u300d\u300c\u4f55\u3092\u300d\u300c\u3069\u3053\u3067\u300d\u3067\u304d\u308b\u306e\u304b<\/strong> \u3092\u660e\u78ba\u306b\u8a2d\u5b9a\u3067\u304d\u307e\u3059\u3002<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\u2705 \u306a\u305cRBAC\u304c\u5fc5\u8981\u306a\u306e\uff1f<\/h3>\n\n\n\n<p>Kubernetes\u30af\u30e9\u30b9\u30bf\u30fc\u3067\u306f\u3001\u591a\u304f\u306e\u30ea\u30bd\u30fc\u30b9\uff08Pod\u3001Service\u3001Secret\u306a\u3069\uff09\u3068\u3001\u591a\u304f\u306e\u30e6\u30fc\u30b6\u30fc\uff08\u958b\u767a\u8005\u3001CI\/CD\u30c4\u30fc\u30eb\u3001\u7ba1\u7406\u8005\u306a\u3069\uff09\u304c\u5b58\u5728\u3057\u307e\u3059\u3002<br>\u305d\u306e\u305f\u3081\u3001\u5168\u54e1\u306b\u30d5\u30eb\u30a2\u30af\u30bb\u30b9\u3092\u8a31\u3057\u3066\u3057\u307e\u3046\u3068<strong>\u4e8b\u6545\u3084\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u30ea\u30b9\u30af\u304c\u5897\u5927<\/strong>\u3057\u307e\u3059\u3002<\/p>\n\n\n\n<p>RBAC\u3092\u4f7f\u3046\u3053\u3068\u3067\uff1a<\/p>\n\n\n\n<ul>\n<li>\u7279\u5b9a\u306e\u30e6\u30fc\u30b6\u30fc\u306b\u300cPod\u306e\u53c2\u7167\u3060\u3051\u8a31\u53ef\u300d\u306a\u3069\u306e\u5236\u9650\u304c\u3067\u304d\u308b<\/li>\n\n\n\n<li>\u30c1\u30fc\u30e0\u3054\u3068\u306b\u30a2\u30af\u30bb\u30b9\u7bc4\u56f2\u3092\u5206\u96e2\u3067\u304d\u308b<\/li>\n\n\n\n<li>\u6700\u5c0f\u6a29\u9650\u306e\u539f\u5247\uff08\u5fc5\u8981\u306a\u6a29\u9650\u3060\u3051\u4e0e\u3048\u308b\uff09\u3092\u5b9f\u73fe\u3067\u304d\u308b<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83e\udde9 RBAC\u306e\u57fa\u672c\u69cb\u6210<\/h3>\n\n\n\n<p>RBAC\u3067\u306f\u4e3b\u306b\u4ee5\u4e0b\u306e4\u3064\u306e\u30ea\u30bd\u30fc\u30b9\u304c\u767b\u5834\u3057\u307e\u3059\uff1a<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>\u30ea\u30bd\u30fc\u30b9<\/th><th>\u5f79\u5272<\/th><\/tr><\/thead><tbody><tr><td><strong>Role<\/strong> \/ <strong>ClusterRole<\/strong><\/td><td>\u3069\u3093\u306a\u64cd\u4f5c\u3092\u8a31\u53ef\u3059\u308b\u304b\uff08\u4f8b: Pod\u306e\u53d6\u5f97\uff09<\/td><\/tr><tr><td><strong>RoleBinding<\/strong> \/ <strong>ClusterRoleBinding<\/strong><\/td><td>\u8ab0\u306b\u305d\u306e\u30ed\u30fc\u30eb\u3092\u5272\u308a\u5f53\u3066\u308b\u304b<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>\u7c21\u5358\u306b\u8a00\u3046\u3068\uff1a<\/p>\n\n\n\n<ul>\n<li><strong>Role<\/strong> \u306f <strong>Namespace\u5358\u4f4d<\/strong> \u306e\u6a29\u9650<\/li>\n\n\n\n<li><strong>ClusterRole<\/strong> \u306f <strong>\u30af\u30e9\u30b9\u30bf\u5168\u4f53<\/strong> \u306b\u307e\u305f\u304c\u308b\u6a29\u9650<\/li>\n\n\n\n<li><strong>RoleBinding<\/strong> \/ <strong>ClusterRoleBinding<\/strong> \u3067 <strong>\u30e6\u30fc\u30b6\u30fc\uff08\u307e\u305f\u306fServiceAccount\uff09\u306b\u30ed\u30fc\u30eb\u3092\u7d10\u3065\u3051<\/strong>\u307e\u3059<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83e\uddea \u4f8b\uff1a\u7279\u5b9aNamespace\u5185\u3067Pod\u306e\u4e00\u89a7\u53d6\u5f97\u3060\u3051\u8a31\u53ef\u3059\u308b<\/h3>\n\n\n\n<div class=\"hcb_wrap\"><pre class=\"prism line-numbers lang-scss\" data-lang=\"SCSS\"><code># Role\u306e\u5b9a\u7fa9\napiVersion: rbac.authorization.k8s.io\/v1\nkind: Role\nmetadata:\n  namespace: dev-team\n  name: pod-reader\nrules:\n  - apiGroups: [&quot;&quot;]\n    resources: [&quot;pods&quot;]\n    verbs: [&quot;get&quot;, &quot;list&quot;]<\/code><\/pre><\/div>\n\n\n\n<div class=\"hcb_wrap\"><pre class=\"prism line-numbers lang-scss\" data-lang=\"SCSS\"><code># RoleBinding\u306e\u5b9a\u7fa9\napiVersion: rbac.authorization.k8s.io\/v1\nkind: RoleBinding\nmetadata:\n  name: read-pods-binding\n  namespace: dev-team\nsubjects:\n  - kind: User\n    name: &quot;alice&quot;\n    apiGroup: rbac.authorization.k8s.io\nroleRef:\n  kind: Role\n  name: pod-reader\n  apiGroup: rbac.authorization.k8s.io<\/code><\/pre><\/div>\n\n\n\n<p>\u3053\u306e\u4f8b\u3067\u306f\uff1a<\/p>\n\n\n\n<ul>\n<li><code>alice<\/code> \u3068\u3044\u3046\u30e6\u30fc\u30b6\u30fc\u306f <code>dev-team<\/code> \u540d\u524d\u7a7a\u9593\u306e Pod \u306b\u5bfe\u3057\u3066 <code>get<\/code> \/ <code>list<\/code> \u304c\u3067\u304d\u307e\u3059<\/li>\n\n\n\n<li>\u4ed6\u306e\u30ea\u30bd\u30fc\u30b9\uff08Secret\u306a\u3069\uff09\u3084\u4ed6\u306eNamespace\u306b\u306f\u30a2\u30af\u30bb\u30b9\u3067\u304d\u307e\u305b\u3093<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83d\udee1 \u30ed\u30fc\u30eb\u8a2d\u8a08\u306e\u30dd\u30a4\u30f3\u30c8<\/h3>\n\n\n\n<ol>\n<li><strong>\u6700\u5c0f\u6a29\u9650\u306e\u539f\u5247<\/strong>\u3092\u610f\u8b58\u3059\u308b<br>\u2192 \u5fc5\u8981\u6700\u5c0f\u9650\u306e <code>verbs<\/code>\u30fb<code>resources<\/code> \u3092\u8a31\u53ef<\/li>\n\n\n\n<li><strong>Namespace\u3054\u3068\u306e\u5206\u96e2<\/strong><br>\u2192 \u30c1\u30fc\u30e0\u3054\u3068\u306b Role\/RoleBinding \u3092\u5206\u3051\u308b\u3068\u7ba1\u7406\u3057\u3084\u3059\u3044<\/li>\n\n\n\n<li><strong>ClusterRole \u306f\u614e\u91cd\u306b<\/strong><br>\u2192 <code>ClusterRole<\/code> \u306f\u5f37\u529b\u306a\u306e\u3067\u3001\u57fa\u672c\u7684\u306b\u306f\u7ba1\u7406\u8005\u3084CI\/CD\u306b\u9650\u5b9a\u3059\u308b<\/li>\n\n\n\n<li><strong>ServiceAccount \u306b\u30d0\u30a4\u30f3\u30c9\u3059\u308b\u3053\u3068\u3067\u3001\u30a2\u30d7\u30ea\u306b\u6a29\u9650\u3092\u4e0e\u3048\u308b<\/strong><br>\u2192 \u4eba\u3060\u3051\u3067\u306a\u304f\u3001\u30a2\u30d7\u30ea\uff08Pod\uff09\u306b\u3082\u8a8d\u8a3c\u30fb\u8a8d\u53ef\u304c\u5fc5\u8981\u306a\u5834\u9762\u3067\u4f7f\u3046<\/li>\n<\/ol>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83d\udca1 \u3088\u304f\u3042\u308b\u30e6\u30fc\u30b9\u30b1\u30fc\u30b9<\/h3>\n\n\n\n<figure class=\"wp-block-table\"><table><thead><tr><th>\u30e6\u30fc\u30b9\u30b1\u30fc\u30b9<\/th><th>\u4f7f\u7528\u3059\u308b\u30ea\u30bd\u30fc\u30b9<\/th><\/tr><\/thead><tbody><tr><td>\u30c1\u30fc\u30e0\u3054\u3068\u306b Namespace \u5185\u30ea\u30bd\u30fc\u30b9\u3092\u64cd\u4f5c\u53ef\u80fd\u306b\u3059\u308b<\/td><td><code>Role + RoleBinding<\/code><\/td><\/tr><tr><td>CI\/CD\u30c4\u30fc\u30eb\u306b\u30af\u30e9\u30b9\u30bf\u5168\u4f53\u306e\u30c7\u30d7\u30ed\u30a4\u6a29\u9650\u3092\u4e0e\u3048\u308b<\/td><td><code>ClusterRole + ClusterRoleBinding<\/code><\/td><\/tr><tr><td>Pod \u306b\u8aad\u307f\u53d6\u308a\u5c02\u7528\u306eSecret\u30a2\u30af\u30bb\u30b9\u3092\u8a31\u53ef<\/td><td><code>Role + RoleBinding<\/code> \u3092 <code>ServiceAccount<\/code> \u306b\u7d10\u4ed8\u3051<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">\ud83d\udccc RBAC\u8a2d\u5b9a\u306e\u78ba\u8a8d\u65b9\u6cd5<\/h3>\n\n\n\n<div class=\"hcb_wrap\"><pre class=\"prism line-numbers lang-bash\" data-lang=\"Bash\"><code># \u3042\u308b\u30e6\u30fc\u30b6\u30fc\u304c Pod \u306e get \u6a29\u9650\u3092\u6301\u3063\u3066\u3044\u308b\u304b\u78ba\u8a8d\nkubectl auth can-i get pods --as alice --namespace dev-team<\/code><\/pre><\/div>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h2 class=\"wp-block-heading\">\ud83d\udd1a \u307e\u3068\u3081<\/h2>\n\n\n\n<p>RBAC\u306fKubernetes\u306b\u304a\u3051\u308b<strong>\u30a2\u30af\u30bb\u30b9\u5236\u5fa1\u306e\u4e2d\u6838<\/strong>\u3067\u3042\u308a\u3001\u5b89\u5168\u306a\u904b\u7528\u306b\u306f\u6b20\u304b\u305b\u307e\u305b\u3093\u3002<\/p>\n\n\n\n<ul>\n<li>\u30ed\u30fc\u30eb\uff08Role \/ ClusterRole\uff09\u3067\u300c\u4f55\u304c\u3067\u304d\u308b\u304b\u300d\u3092\u5b9a\u7fa9\u3057\u3001<\/li>\n\n\n\n<li>\u30d0\u30a4\u30f3\u30c7\u30a3\u30f3\u30b0\uff08RoleBinding \/ ClusterRoleBinding\uff09\u3067\u300c\u8ab0\u304c\u4f7f\u3046\u304b\u300d\u3092\u7d10\u3065\u3051\u307e\u3059\u3002<\/li>\n<\/ul>\n\n\n\n<p>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[55],"tags":[56],"_links":{"self":[{"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/posts\/1477"}],"collection":[{"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/comments?post=1477"}],"version-history":[{"count":1,"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/posts\/1477\/revisions"}],"predecessor-version":[{"id":1478,"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/posts\/1477\/revisions\/1478"}],"wp:attachment":[{"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/media?parent=1477"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/categories?post=1477"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itstudy365.com\/blog\/wp-json\/wp\/v2\/tags?post=1477"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}