Kubernetes permissions KubeEyes needs

KubeEyes can do exactly what your kubeconfig identity is allowed to do. Here is what each part needs.

KubeEyes uses your kubeconfig’s identity and the Kubernetes API, so it can do exactly what that identity is allowed to do — nothing more. Here is what each part uses.

Browsing

Actions

ActionNeeds
Logsget pods/log
Pod shellcreate pods/exec
Node shellcreate pods and create pods/exec in kube-system: it starts a short-lived privileged pod (busybox:1.36) on the node and deletes it when you close the tab
Edit, restart, cordon, drain, suspend, roll backpatch on the object
Scalepatch or update on its scale subresource
Deletedelete
Trigger a CronJobcreate jobs
Port forwardcreate pods/portforward
Prometheus and Lokiget services/proxy in their namespace (details)

Greyed-out actions

KubeEyes asks the cluster once per namespace what you may do (a SelfSubjectRulesReview, cached for a minute) and greys out actions you can’t perform; hovering says which permission is missing. Bulk actions count only the objects you may change and skip the rest. It never blocks on doubt: if the cluster’s authorizer can’t list everything (for example EKS access entries or a webhook) or the check fails, everything stays enabled and the API server has the final say.

A read-only setup

Kubernetes’ built-in view ClusterRole covers browsing most resources (not Secrets) and reading logs. Bound in one namespace:

kubectl create rolebinding kubeeyes-view --clusterrole=view [email protected] -n team-a

For charts and log search, add get on services/proxy in the monitoring namespace. On top of RBAC, KubeEyes’ own Read-only mode (Settings → Clusters) refuses changes and shells for a cluster even when your identity could make them.

Questions

Can I use KubeEyes with read-only Kubernetes access?

Yes. With the built-in view role you can browse resources and read logs; actions you aren’t allowed to do are greyed out with the reason.

Why does a node shell need access to kube-system?

It starts a short-lived privileged pod on that node in kube-system and opens a shell in it, so it needs create on pods and pods/exec there. The pod is deleted when the tab closes.