⚡ ~/naveed k8s
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Phase 1 — Fundamentals Module 08 of 24 Free & Open Access

Namespaces, RBAC & Security Basics

Complete production curriculum breakdown. Learn core architectural mechanics, study definitions in plain language, practice hands-on labs with the local minikube prod-sim cluster, and test active recall.

08 - Namespaces, RBAC & Security Basics

Why this matters

This is how multi-tenant clusters stay safe — who can do what, to which resources, in which namespace. Get this wrong and any compromised pod/service account can become a cluster-admin.

Read this first — Definitions & Explanations

Namespace

A scope for names and access. Lets you split environments/teams (dev, prod) and apply RBAC/quotas per space. Cluster-scoped objects (nodes, PVs, StorageClasses) live outside namespaces.

RBAC

Role-Based Access Control: who can do what on which resources.

Role vs ClusterRole

RoleBinding / ClusterRoleBinding

Binds a Role/ClusterRole to subjects: users, groups, or ServiceAccounts.

ServiceAccount

Identity for processes running in Pods (not humans). Controllers and apps use ServiceAccounts to call the API.

Least privilege

Grant only the verbs/resources needed (get/list/watch on pods — not * on *.*). Over-privileged ServiceAccounts are a common breach path.

Official docs (read for detail)

Key Concepts

YouTube search terms

Hands-on lab (on prod-sim)

kubectl create namespace team-a
kubectl create serviceaccount deployer -n team-a

# Give it permission to only manage deployments in team-a, nothing else
cat <<EOF | kubectl apply -f -
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  namespace: team-a
  name: deployment-manager
rules:
- apiGroups: ["apps"]
  resources: ["deployments"]
  verbs: ["get","list","watch","create","update","patch","delete"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
  name: deployer-binding
  namespace: team-a
subjects:
- kind: ServiceAccount
  name: deployer
  namespace: team-a
roleRef:
  kind: Role
  name: deployment-manager
  apiGroup: rbac.authorization.k8s.io
EOF

# Prove the scoped permissions
kubectl auth can-i create deployments --as=system:serviceaccount:team-a:deployer -n team-a   # yes
kubectl auth can-i delete secrets --as=system:serviceaccount:team-a:deployer -n team-a       # no
kubectl auth can-i create deployments --as=system:serviceaccount:team-a:deployer -n default  # no (namespace-scoped)

# See what the default ServiceAccount can do (should be almost nothing by default)
kubectl auth can-i --list --as=system:serviceaccount:team-a:default -n team-a

# Disable auto-mounting the SA token where it's not needed (good hardening habit)
kubectl patch serviceaccount default -n team-a -p '{"automountServiceAccountToken": false}'

Notes

(fill in your own words after watching + labbing)

📋 Self-Assessment Mastery Checklist (4 Competencies)
🧠 Practice Exam Questions (Module 08 MCQs)
⚡ Take Quiz & Save Progress in Tracker

Review these sample exam questions out loud, test your retrieval, and then unlock official scoring in the interactive tracker.

Question 1: RBAC Role vs ClusterRole:
  • A. Role is namespace-scoped; ClusterRole is cluster-scoped
  • B. They are identical
  • C. Role is only for nodes
  • D. ClusterRole cannot bind to users
✓ Correct Answer: A (Role is namespace-scoped; ClusterRole is cluster-scoped)
Option A ('Role is namespace-scoped; ClusterRole is cluster-scoped') is the standard production architectural best practice.
Question 2: A RoleBinding grants permissions to:
  • A. Subjects (users/groups/serviceAccounts) in a namespace
  • B. All Pods worldwide
  • C. etcd exclusively
  • D. CNI plugins
✓ Correct Answer: A (Subjects (users/groups/serviceAccounts) in a namespace)
Option A ('Subjects (users/groups/serviceAccounts) in a namespace') is the standard production architectural best practice.
Question 3: Namespaces are used to:
  • A. Partition cluster resources and scope access
  • B. Replace nodes
  • C. Store only Secrets
  • D. Disable the API server
✓ Correct Answer: A (Partition cluster resources and scope access)
Option A ('Partition cluster resources and scope access') is the standard production architectural best practice.
Question 4: ServiceAccounts are primarily for:
  • A. Human laptop logins only
  • B. Pod/process identity in-cluster
  • C. DNS resolution
  • D. Image compression
✓ Correct Answer: B (Pod/process identity in-cluster)
Option B ('Pod/process identity in-cluster') is the standard production architectural best practice.
Question 5: Least privilege means:
  • A. Grant only the permissions needed
  • B. Give cluster-admin to all apps
  • C. Disable RBAC
  • D. Share one ServiceAccount everywhere
✓ Correct Answer: A (Grant only the permissions needed)
Option A ('Grant only the permissions needed') is the standard production architectural best practice.
← Previous Module (07) Ingress & Ingress Controllers Next Module (09) → Helm & Package Management