kodebeat / papers / security
Making Kubernetes RBAC drift visible before an incident does
An RBAC reporter with snapshot diffing and who-can queries.
Dumps and diffs Kubernetes RBAC into reports a human will actually read: wildcard grants, cluster-admin bindings, unused ServiceAccounts, dangling bindings, who-can queries and snapshot diffing for change tracking. Markdown or HTML, with --fail-on-findings for CI and an ignore file for accepted exceptions, and a CronJob manifest, because the intended use is a weekly report rather than an annual audit.
What is in it
- The problem — what goes unanswered without it, and who notices first.
- Why the obvious alternative falls short — stated plainly, including where it is the better choice.
- How it works — the method, not a feature list.
- Concrete use cases — with console output quoted from the repository, never reconstructed.
- The methodology behind any number it emits — every term shown, so the figure survives a question.
- What it deliberately does not do — the section most papers leave out.
Part of the Security & supply chain theme.
Get the PDF
One email with the download link, and this paper already selected. No follow-up sequence.