alcideio / rbac-tool

Rapid7 | insightCloudSec | Kubernetes RBAC Power Toys - Visualize, Analyze, Generate & Query

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Analysis/Audit rule listing bindings for non-existant accounts

fuero opened this issue · comments

What would you like to be added:
I'd like `rbac-tool analyze' warn about (Cluster)Rolebindings for accounts that don't or no longer exist in the cluster.

Why is this needed:
Unnecessary permissions are a security risk and should be audited.