<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>RBAC on Zhao Xue</title><link>https://xuezhaojun.github.io/tags/rbac/</link><description>Recent content in RBAC on Zhao Xue</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 24 Apr 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://xuezhaojun.github.io/tags/rbac/index.xml" rel="self" type="application/rss+xml"/><item><title>从一次 pods/exec forbidden 聊起：彻底搞懂 K8s RBAC 权限模型</title><link>https://xuezhaojun.github.io/collections/k8s-internals/k8s-rbac/</link><pubDate>Fri, 24 Apr 2026 00:00:00 +0000</pubDate><guid>https://xuezhaojun.github.io/collections/k8s-internals/k8s-rbac/</guid><description>kubectl get pods 正常，但 kubectl exec 报 forbidden: cannot create resource pods/exec。排查过程揭开 RBAC 的全部细节：Role 和 ClusterRole 的作用域、Binding 的组合关系、ServiceAccount 的 Token 演进、子资源权限的隐藏坑，以及多租户隔离的最佳实践。</description></item></channel></rss>