T3system:discoverycluster
Read access to API discovery endpoints.
Allows enumerating available API groups, versions, resource types, and server version information.
- →
Bound to 'system:authenticated' by default and commonly also available in limited form to unauthenticated clients.
- →
Restricting discovery can break kubectl and client tooling; limit unauthenticated network access at the infrastructure level instead.
Permissions (1)
| apiGroup | resources / urls | verbs |
|---|---|---|
| (non-resource) | /api, /api/*, /apis, /apis/*, /healthz, /livez, /openapi, /openapi/*, /readyz, /version, /version/ | get |
Audit: NoneK8s docs ↗
