T3system:public-info-viewercluster
Allows reading non-sensitive public cluster information such as health, readiness, liveness, and version endpoints.
- →
Bound to both 'system:authenticated' and 'system:unauthenticated'; truly public to the network.
- →
Exposes the Kubernetes version string, which helps attackers target known version-specific CVEs.
Permissions (1)
| apiGroup | resources / urls | verbs |
|---|---|---|
| (non-resource) | /healthz, /livez, /readyz, /version, /version/ | get |
Audit: NoneK8s docs ↗
