
Kubesplaining now has a least privileged mode. Point it to kube-apiserver audit logs and it tells you exactly which RBAC verbs your ServiceAccounts were granted but never used.
github.com/0hardik1/kubes…

Hardik Darji@HRDARJI
Shipping Kubesplaining v1.0 today. A Kubernetes security CLI that maps every RBAC subject's privilege-escalation paths to cluster-admin, host root, and kube-system secrets, and shows you the chains.
English















