Kubetier
T2system:node-proxiercluster

kube-proxy identity with list/watch access to Services, Endpoints, EndpointSlices, and Nodes to maintain service routing rules.

  • Bound to the kube-proxy ServiceAccount by default.

  • Cluster-wide watch on Services, Endpoints, and EndpointSlices provides full service-routing topology visibility to any holder of this role.

Permissions (5)
apiGroupresources / urlsverbs
""endpoints, serviceslist watch
""nodesget list watch
"", events.k8s.ioeventscreate patch update
networking.k8s.ioservicecidrslist watch
discovery.k8s.ioendpointsliceslist watch
Audit: MetadataK8s docs ↗