Skip to main content
在 Manus 中运行任何 Skill
一键导入

rbac-whocan

星标4
分支2
更新时间2026年7月1日 03:04

Answer Kubernetes effective-access questions across a ConfigHub fleet with the cub-rbac CLI: "who can VERB RESOURCE?" and the inverse "what can SUBJECT do?". Use for "who can delete secrets in prod?", "who can exec into pods?", "what can the ci-deployer service account do?", "which subjects have access to configmaps in payments?", "can anyone create clusterrolebindings?". Resolves RoleBindings/ClusterRoleBindings through their roles (including ClusterRole aggregation) and honors namespace scope and resourceNames. Not for inventory/listing (use rbac-audit) or risk/hygiene findings (use rbac-findings); not for live cluster authorization (use kubectl auth can-i).

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

文件资源管理器
2 个文件
SKILL.md
readonly