Topic 1: API Access Control

Official baseline: (The Kubernetes Authors, 2026). My working version: Every meaningful Kubernetes action becomes an API request that must authenticate, authorize, and pass admission.

Mental Model

Every meaningful Kubernetes action becomes an API request that must authenticate, authorize, and pass admission.

Notes

  • Authentication answers who you are.
  • Authorization answers what you can do.
  • Admission answers whether the request is acceptable now.

Homelab Angle

Create a non-admin user early. It changes how you see the platform.

Verify It

  • Read the object status before changing the manifest.
  • Check events for the controller or node that is actually complaining.
  • Confirm the official source linked below still matches the cluster version you run.

Common Failure Modes

  • Treating the YAML object as the system, instead of one input to a reconciliation loop.
  • Debugging from outside the cluster when the failure only exists inside cluster networking or node state.
  • Forgetting that Kubernetes version, addon version, and runtime behavior are linked.

Sources

  • Controlling Access to the Kubernetes API - source path: content/en/docs/concepts/security/controlling-access.md, commit 8cc9e19b8eec8d5cf49eacd66f86a81648edb1a0.
  • Kubernetes documentation is licensed under CC BY 4.0; these notes are original commentary and link back to the official source.
The Kubernetes Authors. (2026). Controlling Access to the Kubernetes API. https://kubernetes.io/docs/concepts/security/controlling-access/