Built-In Role Summary
Role
Scope
Intended use
Notable limits
Last updated

cluster-admin
Cluster-wide
Full cluster administration
No practical restrictions
admin
Namespace when bound with
a
RoleBinding
Namespace administrators
Not cluster-wide by itself
edit
Namespace when bound with
a
RoleBinding
Developers who need read/write access
Does not manage RBAC policy
view
Namespace when bound with
a
RoleBinding
Read-only users
Cannot read
Secret
objects by default
Last updated