本文へ移動
cccskills
無料GitHub で公開

rbac-patterns

Skill for rbac-patterns tasks.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md2.2 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

apiVersion: apps/v1 kind: Deployment metadata: name: my-app spec: template: spec: serviceAccountName: my-app automountServiceAccountToken: false # Disable if not needed


### Least-Privilege ServiceAccount

```yaml
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: my-app-role
  namespace: production
rules:
  - apiGroups: [""]
    resources: ["configmaps"]
    verbs: ["get"]
    resourceNames: ["my-app-config"]

Security Best Practices

  1. Use Roles over ClusterRoles when possible
  2. Specify resourceNames for fine-grained access
  3. Avoid wildcard permissions (*) in production
  4. Create dedicated ServiceAccounts for each app
  5. Disable token auto-mounting if not needed
  6. Regular RBAC audits to remove unused permissions
  7. Use groups for user management
  8. Implement namespace isolation
  9. Monitor RBAC usage with audit logs
  10. Document role purposes in metadata

Troubleshooting RBAC

Check User Permissions

kubectl auth can-i list pods --as john@example.com
kubectl auth can-i '*' '*' --as system:serviceaccount:default:my-app

View Effective Permissions

kubectl describe clusterrole cluster-admin
kubectl describe rolebinding -n production

Debug Access Issues

kubectl get rolebindings,clusterrolebindings --all-namespaces -o wide | grep my-user

Common RBAC Verbs

  • get - Read a specific resource
  • list - List all resources of a type
  • watch - Watch for resource changes
  • create - Create new resources
  • update - Update existing resources
  • patch - Partially update resources
  • delete - Delete resources
  • deletecollection - Delete multiple resources
  • * - All verbs (avoid in production)

Resource Scope

Cluster-Scoped Resources

  • Nodes
  • PersistentVolumes
  • ClusterRoles
  • ClusterRoleBindings
  • Namespaces

Namespace-Scoped Resources

  • Pods
  • Services
  • Deployments
  • ConfigMaps
  • Secrets
  • Roles
  • RoleBindings

Output Format

<result>
  <analysis>Brief analysis</analysis>
  <solution>Implementation</solution>
  <considerations>Trade-offs and notes</considerations>
</result>

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Audit UI code for WCAG compliance

日本語の概要は準備中です。原文の説明を表示しています。

itsimonfredlingjack/codex-dev-plugin22026年2月5日 更新

Expert accessibility specialist ensuring WCAG compliance, inclusive design, and assistive technology compatibility. Masters screen reader optimization, keyboard navigation, and a11y testing methodologies. Use PROACTIVELY when auditing accessibility, remediating a11y issues, building accessible components, or ensuring inclusive user experiences.

日本語の概要は準備中です。原文の説明を表示しています。

itsimonfredlingjack/codex-dev-plugin22026年2月5日 更新

Skill for accessibility-patterns tasks.

日本語の概要は準備中です。原文の説明を表示しています。

itsimonfredlingjack/codex-dev-plugin22026年2月5日 更新

Build AI assistant application with NLU, dialog management, and integrations

日本語の概要は準備中です。原文の説明を表示しています。

itsimonfredlingjack/codex-dev-plugin22026年2月5日 更新

Build production-ready LLM applications, advanced RAG systems, and intelligent agents. Implements vector search, multimodal AI, agent orchestration, and enterprise AI integrations. Use PROACTIVELY for LLM features, chatbots, AI agents, or AI-powered applications.

日本語の概要は準備中です。原文の説明を表示しています。

itsimonfredlingjack/codex-dev-plugin22026年2月5日 更新

ai-review

無料

You are an expert AI-powered code review specialist combining automated static analysis, intelligent pattern recognition, and modern DevOps practices. Leverage AI tools (GitHub Copilot, Qodo, GPT-5, Claude 4.5 Sonnet) with battle-tested platforms (SonarQube, CodeQL, Semgrep) to identify bugs, vulnerabilities, and performance issues.

日本語の概要は準備中です。原文の説明を表示しています。

itsimonfredlingjack/codex-dev-plugin22026年2月5日 更新

itsimonfredlingjack のスキルをすべて見る

このスキルの問題を報告する