NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Go modules · #1709 by repository stars
Last release 2 years ago
no release in 18 months
Ships fairly regularly
a new release about every 2 months
Rarely documented
notes for 10 of 50 stable releases
Nothing withdrawn
no release was ever pulled
7 years old
64 releases · first in 2020
One column per quarter.
A collection of Kubernetes RBAC tools to sugar coat Kubernetes RBAC complexity
A collection of Kubernetes RBAC tools to sugar coat Kubernetes RBAC complexity
curl https://raw.githubusercontent.com/alcideio/rbac-tool/master/download.sh | bash$ kubectl krew install rbac-tool# Show which users/groups/service accounts are allowed to read secrets in the cluster pointed by kubeconfig
rbac-tool who-can get secrets
# Show the subject information of the the one authenticates against the current cluster context
rbac-tool whoami
# Scan the cluster pointed by the kubeconfig context 'myctx'
rbac-tool viz --cluster-context myctx
# Scan and create a PNG image from the graph
rbac-tool viz --outformat dot --exclude-namespaces=soemns && cat rbac.dot | dot -Tpng > rbac.png && google-chrome rbac.png
# Render Online
https://dreampuf.github.io/GraphvizOnline
# Analyze cluster RBAC permissions to identify overly permissive roles and principals
rbac-tool analysis -o table
# Search All Service Accounts That Contains myname
rbac-tool lookup -e '.*myname.*'
# Lookup all accounts that DO NOT start with system: )
rbac-tool lookup -ne '^system:.*'
# List policy rules for users (or all of them)
rbac-tool policy-rules -e '^system:anonymous'
# Generate from Audit events & Visualize
rbac-tool auditgen -f testdata | rbac-tool viz -f -
# Generate a `ClusterRole` policy that allows to read everything **except** *secrets* and *services*
rbac-tool gen --deny-resources=secrets.,services. --allowed-verbs=get,list
# Generate a ClusterRole with all the available permissions for core and apps api groups
rbac-tool show --for-groups=,apps
# Generate HTML visualzation of your RBAC permissions
kubectl rbac-tool viz
# Query who can read secrets
kubectl rbac-tool who-can get secret
# Generate a ClusterRole policy that allows to read everything except secrets and services
kubectl rbac-tool gen --deny-resources=secrets.,services. --allowed-verbs=get,list
# Analyze cluster RBAC permissions to identify overly permissive roles and principals
kubectl rbac-tool analysis -o table
# Generate a ClusterRole with all the available permissions for core and apps api groups
kubectl rbac-tool show --for-groups=,apps
# Show the subject information of the the one authenticates against the current cluster context
kubectl rbac-tool whoamiNothing published for this version
A collection of Kubernetes RBAC tools to sugar coat Kubernetes RBAC complexity
A collection of Kubernetes RBAC tools to sugar coat Kubernetes RBAC complexity
curl https://raw.githubusercontent.com/alcideio/rbac-tool/master/download.sh | bash$ kubectl krew install rbac-tool# Show which users/groups/service accounts are allowed to read secrets in the cluster pointed by kubeconfig
rbac-tool who-can get secrets
# Show the subject information of the the one authenticates against the current cluster context
rbac-tool whoami
# Scan the cluster pointed by the kubeconfig context 'myctx'
rbac-tool viz --cluster-context myctx
# Scan and create a PNG image from the graph
rbac-tool viz --outformat dot --exclude-namespaces=soemns && cat rbac.dot | dot -Tpng > rbac.png && google-chrome rbac.png
# Render Online
https://dreampuf.github.io/GraphvizOnline
# Analyze cluster RBAC permissions to identify overly permissive roles and principals
rbac-tool analysis -o table
# Search All Service Accounts That Contains myname
rbac-tool lookup -e '.*myname.*'
# Lookup all accounts that DO NOT start with system: )
rbac-tool lookup -ne '^system:.*'
# List policy rules for users (or all of them)
rbac-tool policy-rules -e '^system:anonymous'
# Generate from Audit events & Visualize
rbac-tool auditgen -f testdata | rbac-tool viz -f -
# Generate a `ClusterRole` policy that allows to read everything **except** *secrets* and *services*
rbac-tool gen --deny-resources=secrets.,services. --allowed-verbs=get,list
# Generate a ClusterRole with all the available permissions for core and apps api groups
rbac-tool show --for-groups=,apps
# Generate HTML visualzation of your RBAC permissions
kubectl rbac-tool viz
# Query who can read secrets
kubectl rbac-tool who-can get secret
# Generate a ClusterRole policy that allows to read everything except secrets and services
kubectl rbac-tool gen --deny-resources=secrets.,services. --allowed-verbs=get,list
# Analyze cluster RBAC permissions to identify overly permissive roles and principals
kubectl rbac-tool analysis -o table
# Generate a ClusterRole with all the available permissions for core and apps api groups
kubectl rbac-tool show --for-groups=,apps
# Show the subject information of the the one authenticates against the current cluster context
kubectl rbac-tool whoamiNothing published for this version
A collection of Kubernetes RBAC tools to sugar coat Kubernetes RBAC complexity
A collection of Kubernetes RBAC tools to sugar coat Kubernetes RBAC complexity
curl https://raw.githubusercontent.com/alcideio/rbac-tool/master/download.sh | bash$ kubectl krew install rbac-tool# Show which users/groups/service accounts are allowed to read secrets in the cluster pointed by kubeconfig
rbac-tool who-can get secrets
# Show the subject information of the the one authenticates against the current cluster context
rbac-tool whoami
# Scan the cluster pointed by the kubeconfig context 'myctx'
rbac-tool viz --cluster-context myctx
# Scan and create a PNG image from the graph
rbac-tool viz --outformat dot --exclude-namespaces=soemns && cat rbac.dot | dot -Tpng > rbac.png && google-chrome rbac.png
# Render Online
https://dreampuf.github.io/GraphvizOnline
# Analyze cluster RBAC permissions to identify overly permissive roles and principals
rbac-tool analysis -o table
# Search All Service Accounts That Contains myname
rbac-tool lookup -e '.*myname.*'
# Lookup all accounts that DO NOT start with system: )
rbac-tool lookup -ne '^system:.*'
# List policy rules for users (or all of them)
rbac-tool policy-rules -e '^system:anonymous'
# Generate from Audit events & Visualize
rbac-tool auditgen -f testdata | rbac-tool viz -f -
# Generate a `ClusterRole` policy that allows to read everything **except** *secrets* and *services*
rbac-tool gen --deny-resources=secrets.,services. --allowed-verbs=get,list
# Generate a ClusterRole with all the available permissions for core and apps api groups
rbac-tool show --for-groups=,apps
# Generate HTML visualzation of your RBAC permissions
kubectl rbac-tool viz
# Query who can read secrets
kubectl rbac-tool who-can get secret
# Generate a ClusterRole policy that allows to read everything except secrets and services
kubectl rbac-tool gen --deny-resources=secrets.,services. --allowed-verbs=get,list
# Analyze cluster RBAC permissions to identify overly permissive roles and principals
kubectl rbac-tool analysis -o table
# Generate a ClusterRole with all the available permissions for core and apps api groups
kubectl rbac-tool show --for-groups=,apps
# Show the subject information of the the one authenticates against the current cluster context
kubectl rbac-tool whoamiA collection of Kubernetes RBAC tools to sugar coat Kubernetes RBAC complexity
A collection of Kubernetes RBAC tools to sugar coat Kubernetes RBAC complexity
curl https://raw.githubusercontent.com/alcideio/rbac-tool/master/download.sh | bash$ kubectl krew install rbac-tool# Show which users/groups/service accounts are allowed to read secrets in the cluster pointed by kubeconfig
rbac-tool who-can get secrets
# Show the subject information of the the one authenticates against the current cluster context
rbac-tool whoami
# Scan the cluster pointed by the kubeconfig context 'myctx'
rbac-tool viz --cluster-context myctx
# Scan and create a PNG image from the graph
rbac-tool viz --outformat dot --exclude-namespaces=soemns && cat rbac.dot | dot -Tpng > rbac.png && google-chrome rbac.png
# Render Online
https://dreampuf.github.io/GraphvizOnline
# Analyze cluster RBAC permissions to identify overly permissive roles and principals
rbac-tool analysis -o table
# Search All Service Accounts That Contains myname
rbac-tool lookup -e '.*myname.*'
# Lookup all accounts that DO NOT start with system: )
rbac-tool lookup -ne '^system:.*'
# List policy rules for users (or all of them)
rbac-tool policy-rules -e '^system:anonymous'
# Generate from Audit events & Visualize
rbac-tool auditgen -f testdata | rbac-tool viz -f -
# Generate a `ClusterRole` policy that allows to read everything **except** *secrets* and *services*
rbac-tool gen --deny-resources=secrets.,services. --allowed-verbs=get,list
# Generate a ClusterRole with all the available permissions for core and apps api groups
rbac-tool show --for-groups=,apps
# Generate HTML visualzation of your RBAC permissions
kubectl rbac-tool viz
# Query who can read secrets
kubectl rbac-tool who-can get secret
# Generate a ClusterRole policy that allows to read everything except secrets and services
kubectl rbac-tool gen --deny-resources=secrets.,services. --allowed-verbs=get,list
# Analyze cluster RBAC permissions to identify overly permissive roles and principals
kubectl rbac-tool analysis -o table
# Generate a ClusterRole with all the available permissions for core and apps api groups
kubectl rbac-tool show --for-groups=,apps
# Show the subject information of the the one authenticates against the current cluster context
kubectl rbac-tool whoamiA collection of Kubernetes RBAC tools to sugar coat Kubernetes RBAC complexity
A collection of Kubernetes RBAC tools to sugar coat Kubernetes RBAC complexity
curl https://raw.githubusercontent.com/alcideio/rbac-tool/master/download.sh | bash$ kubectl krew install rbac-tool# Show which users/groups/service accounts are allowed to read secrets in the cluster pointed by kubeconfig
rbac-tool who-can get secrets
# Show the subject information of the the one authenticates against the current cluster context
rbac-tool whoami
# Scan the cluster pointed by the kubeconfig context 'myctx'
rbac-tool viz --cluster-context myctx
# Scan and create a PNG image from the graph
rbac-tool viz --outformat dot --exclude-namespaces=soemns && cat rbac.dot | dot -Tpng > rbac.png && google-chrome rbac.png
# Render Online
https://dreampuf.github.io/GraphvizOnline
# Analyze cluster RBAC permissions to identify overly permissive roles and principals
rbac-tool analysis -o table
# Search All Service Accounts That Contains myname
rbac-tool lookup -e '.*myname.*'
# Lookup all accounts that DO NOT start with system: )
rbac-tool lookup -ne '^system:.*'
# List policy rules for users (or all of them)
rbac-tool policy-rules -e '^system:anonymous'
# Generate from Audit events & Visualize
rbac-tool auditgen -f testdata | rbac-tool viz -f -
# Generate a `ClusterRole` policy that allows to read everything **except** *secrets* and *services*
rbac-tool gen --deny-resources=secrets.,services. --allowed-verbs=get,list
# Generate a ClusterRole with all the available permissions for core and apps api groups
rbac-tool show --for-groups=,apps
# Generate HTML visualzation of your RBAC permissions
kubectl rbac-tool viz
# Query who can read secrets
kubectl rbac-tool who-can get secret
# Generate a ClusterRole policy that allows to read everything except secrets and services
kubectl rbac-tool gen --deny-resources=secrets.,services. --allowed-verbs=get,list
# Analyze cluster RBAC permissions to identify overly permissive roles and principals
kubectl rbac-tool analysis -o table
# Generate a ClusterRole with all the available permissions for core and apps api groups
kubectl rbac-tool show --for-groups=,apps
# Show the subject information of the the one authenticates against the current cluster context
kubectl rbac-tool whoamiNothing published for this version
A collection of Kubernetes RBAC tools to sugar coat Kubernetes RBAC complexity
A collection of Kubernetes RBAC tools to sugar coat Kubernetes RBAC complexity
curl https://raw.githubusercontent.com/alcideio/rbac-tool/master/download.sh | bash$ kubectl krew install rbac-tool# Show which users/groups/service accounts are allowed to read secrets in the cluster pointed by kubeconfig
rbac-tool who-can get secrets
# Show the subject information of the the one authenticates against the current cluster context
rbac-tool whoami
# Scan the cluster pointed by the kubeconfig context 'myctx'
rbac-tool viz --cluster-context myctx
# Scan and create a PNG image from the graph
rbac-tool viz --outformat dot --exclude-namespaces=soemns && cat rbac.dot | dot -Tpng > rbac.png && google-chrome rbac.png
# Render Online
https://dreampuf.github.io/GraphvizOnline
# Analyze cluster RBAC permissions to identify overly permissive roles and principals
rbac-tool analysis -o table
# Search All Service Accounts That Contains myname
rbac-tool lookup -e '.*myname.*'
# Lookup all accounts that DO NOT start with system: )
rbac-tool lookup -ne '^system:.*'
# List policy rules for users (or all of them)
rbac-tool policy-rules -e '^system:anonymous'
# Generate from Audit events & Visualize
rbac-tool auditgen -f testdata | rbac-tool viz -f -
# Generate a `ClusterRole` policy that allows to read everything **except** *secrets* and *services*
rbac-tool gen --deny-resources=secrets.,services. --allowed-verbs=get,list
# Generate a ClusterRole with all the available permissions for core and apps api groups
rbac-tool show --for-groups=,apps
# Generate HTML visualzation of your RBAC permissions
kubectl rbac-tool viz
# Query who can read secrets
kubectl rbac-tool who-can get secret
# Generate a ClusterRole policy that allows to read everything except secrets and services
kubectl rbac-tool gen --deny-resources=secrets.,services. --allowed-verbs=get,list
# Analyze cluster RBAC permissions to identify overly permissive roles and principals
kubectl rbac-tool analysis -o table
# Generate a ClusterRole with all the available permissions for core and apps api groups
kubectl rbac-tool show --for-groups=,apps
# Show the subject information of the the one authenticates against the current cluster context
kubectl rbac-tool whoamiA collection of Kubernetes RBAC tools to sugar coat Kubernetes RBAC complexity
A collection of Kubernetes RBAC tools to sugar coat Kubernetes RBAC complexity
curl https://raw.githubusercontent.com/alcideio/rbac-tool/master/download.sh | bash$ kubectl krew install rbac-tool# Show which users/groups/service accounts are allowed to read secrets in the cluster pointed by kubeconfig
rbac-tool who-can get secrets
# Show the subject information of the the one authenticates against the current cluster context
rbac-tool whoami
# Scan the cluster pointed by the kubeconfig context 'myctx'
rbac-tool viz --cluster-context myctx
# Scan and create a PNG image from the graph
rbac-tool viz --outformat dot --exclude-namespaces=soemns && cat rbac.dot | dot -Tpng > rbac.png && google-chrome rbac.png
# Render Online
https://dreampuf.github.io/GraphvizOnline
# Analyze cluster RBAC permissions to identify overly permissive roles and principals
rbac-tool analysis -o table
# Search All Service Accounts That Contains myname
rbac-tool lookup -e '.*myname.*'
# Lookup all accounts that DO NOT start with system: )
rbac-tool lookup -ne '^system:.*'
# List policy rules for users (or all of them)
rbac-tool policy-rules -e '^system:anonymous'
# Generate from Audit events & Visualize
rbac-tool auditgen -f testdata | rbac-tool viz -f -
# Generate a `ClusterRole` policy that allows to read everything **except** *secrets* and *services*
rbac-tool gen --deny-resources=secrets.,services. --allowed-verbs=get,list
# Generate a ClusterRole with all the available permissions for core and apps api groups
rbac-tool show --for-groups=,apps
# Generate HTML visualzation of your RBAC permissions
kubectl rbac-tool viz
# Query who can read secrets
kubectl rbac-tool who-can get secret
# Generate a ClusterRole policy that allows to read everything except secrets and services
kubectl rbac-tool gen --deny-resources=secrets.,services. --allowed-verbs=get,list
# Analyze cluster RBAC permissions to identify overly permissive roles and principals
kubectl rbac-tool analysis -o table
# Generate a ClusterRole with all the available permissions for core and apps api groups
kubectl rbac-tool show --for-groups=,apps
# Show the subject information of the the one authenticates against the current cluster context
kubectl rbac-tool whoamiA collection of Kubernetes RBAC tools to sugar coat Kubernetes RBAC complexity
A collection of Kubernetes RBAC tools to sugar coat Kubernetes RBAC complexity
curl https://raw.githubusercontent.com/alcideio/rbac-tool/master/download.sh | bash$ kubectl krew install rbac-tool# Show which users/groups/service accounts are allowed to read secrets in the cluster pointed by kubeconfig
rbac-tool who-can get secrets
# Show the subject information of the the one authenticates against the current cluster context
rbac-tool whoami
# Scan the cluster pointed by the kubeconfig context 'myctx'
rbac-tool viz --cluster-context myctx
# Scan and create a PNG image from the graph
rbac-tool viz --outformat dot --exclude-namespaces=soemns && cat rbac.dot | dot -Tpng > rbac.png && google-chrome rbac.png
# Render Online
https://dreampuf.github.io/GraphvizOnline
# Analyze cluster RBAC permissions to identify overly permissive roles and principals
rbac-tool analysis -o table
# Search All Service Accounts That Contains myname
rbac-tool lookup -e '.*myname.*'
# Lookup all accounts that DO NOT start with system: )
rbac-tool lookup -ne '^system:.*'
# List policy rules for users (or all of them)
rbac-tool policy-rules -e '^system:anonymous'
# Generate from Audit events & Visualize
rbac-tool auditgen -f testdata | rbac-tool viz -f -
# Generate a `ClusterRole` policy that allows to read everything **except** *secrets* and *services*
rbac-tool gen --deny-resources=secrets.,services. --allowed-verbs=get,list
# Generate a ClusterRole with all the available permissions for core and apps api groups
rbac-tool show --for-groups=,apps
# Generate HTML visualzation of your RBAC permissions
kubectl rbac-tool viz
# Query who can read secrets
kubectl rbac-tool who-can get secret
# Generate a ClusterRole policy that allows to read everything except secrets and services
kubectl rbac-tool gen --deny-resources=secrets.,services. --allowed-verbs=get,list
# Analyze cluster RBAC permissions to identify overly permissive roles and principals
kubectl rbac-tool analysis -o table
# Generate a ClusterRole with all the available permissions for core and apps api groups
kubectl rbac-tool show --for-groups=,apps
# Show the subject information of the the one authenticates against the current cluster context
kubectl rbac-tool whoamiv1.14.3 Compare # Choose a tag to compare
v1.14.3
Compare
v1.14.2 Compare # Choose a tag to compare
v1.14.2
Compare
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →