Memory hook: Context selects the destination; authentication proves identity; authorisation grants actions; admission checks the change.
Must remember
- kubectl is a client of the Kubernetes API. A kubeconfig context combines a cluster, credentials and a default namespace. Check the context before acting; an accurate command aimed at the wrong cluster is still wrong.
getlists objects,describeadds object details and events, andexplaindescribes API fields.-n team-achooses a namespace;-Alists across namespaces when authorised.-o yamlor-o jsonexposes object structure.- Imperative commands describe an immediate operation, such as creating an object. Declarative management records the desired configuration in manifests and applies it repeatedly.
kubectl apply -f file.yamlsubmits desired configuration; it does not establish a continuously running GitOps controller. - A ConfigMap carries non-confidential settings. A Secret carries sensitive values and can be mounted or injected into a Pod. Base64 in a Secret manifest is encoding, not encryption; encryption at rest, restricted access and safe handling are separate controls.
- Mounted configuration can update over time, but an application must notice and reload it. Values injected as environment variables do not automatically change in an existing process; replacing Pods is often the intended rollout mechanism.
- Authentication determines who makes an API request. Authorisation, commonly RBAC, determines whether that identity may perform the requested verb on the resource. Admission can validate or mutate an authorised object-creation or modification request before persistence.
- Role and RoleBinding usually express permissions within a namespace. ClusterRole defines reusable or cluster-scoped permissions. A RoleBinding can reference a ClusterRole but grants applicable permissions only in the binding's namespace; a ClusterRoleBinding grants across the cluster.
- ServiceAccounts are workload identities. Prefer short-lived, scoped credentials and omit API token mounting when an application does not need Kubernetes API access. Grant least privilege; a namespace does not justify giving every application cluster-admin.
- Pod Security Standards offer Privileged, Baseline and Restricted profiles. Pod Security Admission can enforce, warn or audit at namespace scope. Application identity, network policy and container hardening protect different layers.
Read-only command recognition:
kubectl config current-context
kubectl get pods -n team-a -o wide
kubectl describe pod app -n team-a
kubectl explain deployment.spec
kubectl auth can-i get secrets -n team-a
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Keep a non-sensitive API endpoint outside the image | ConfigMap; rebuilds should not be necessary for each environment setting |
| Allow a workload to read only selected resources in its namespace | A ServiceAccount with narrowly scoped RBAC |
| Check whether the current identity may list Pods | kubectl auth can-i list pods in the intended namespace |
| Reject privileged workloads during admission | Appropriate Pod Security Admission enforcement or another suitable admission policy |
| Identify why a user receives Forbidden after logging in | Investigate authorisation, bindings, verbs and resource scope |
Traps
- Possessing a valid identity does not imply permission to perform every action.
- A Secret object is not automatically encrypted merely because its YAML looks unreadable.
- Listing or watching Secrets can expose secret data; “read-only” is not necessarily harmless.
- ConfigMap or Secret changes do not rebuild an image or automatically restart every consumer.
Active recall
1. A request reaches the API as the correct user but receives Forbidden. Which check is the likely issue?
Authorisation. Inspect the requested resource, verb, namespace and relevant role bindings. Authentication identifies the caller; it does not grant permission on its own.
2. A RoleBinding in namespace payments refers to a ClusterRole. Does it grant access in every namespace?
No. The RoleBinding limits the applicable permissions to payments. A ClusterRoleBinding is the object that grants a ClusterRole's permissions across the cluster.
3. An operator updates a ConfigMap used as an environment variable. Why does the running application still see the old value?
The environment was set when the container started. Replace the Pod or use a deliberate configuration reload design. A mounted file has different update behaviour, and the application still needs to consume the change.
4. Does base64 encoding prevent someone who can read a Secret from recovering its contents?
No. Base64 is reversible encoding. Protect Secret access with RBAC and workload controls, use encryption at rest where configured, and keep values out of logs and source control.
5. What should you inspect before using kubectl against an unfamiliar environment?
The current context, which selects the cluster, credentials and default namespace. Then confirm the explicit namespace and the operation's scope before making changes.