RBAC Architecture
vCluster uses a two-tier RBAC model:- Host Cluster RBAC: Controls what vCluster can do in the host cluster
- Virtual Cluster RBAC: Controls what users can do inside the vCluster
Host Cluster RBAC
vCluster requires specific permissions in the host cluster to function. These permissions are managed through Kubernetes RBAC resources.ClusterRole Permissions
When vCluster needs cluster-wide permissions, a ClusterRole is created:chart/templates/clusterrole.yaml: