Kubetier
T3system:discoverycluster

Read access to API discovery endpoints.

Allows enumerating available API groups, versions, resource types, and server version information.

  • Bound to 'system:authenticated' by default and commonly also available in limited form to unauthenticated clients.

  • Restricting discovery can break kubectl and client tooling; limit unauthenticated network access at the infrastructure level instead.

Permissions (1)
apiGroupresources / urlsverbs
(non-resource)/api, /api/*, /apis, /apis/*, /healthz, /livez, /openapi, /openapi/*, /readyz, /version, /version/get
Audit: NoneK8s docs ↗