Kubetier
T3system:public-info-viewercluster

Allows reading non-sensitive public cluster information such as health, readiness, liveness, and version endpoints.

  • Bound to both 'system:authenticated' and 'system:unauthenticated'; truly public to the network.

  • Exposes the Kubernetes version string, which helps attackers target known version-specific CVEs.

Permissions (1)
apiGroupresources / urlsverbs
(non-resource)/healthz, /livez, /readyz, /version, /version/get
Audit: NoneK8s docs ↗