Lineage
read-only · v1.0
static mock demo — no cluster connection, no oc, no credentials
Static mock demo. This page uses a small bundled sample dataset. It does not connect to a cluster, run oc, or read local credentials.

Aggregated ClusterRoles

Roles whose aggregationRule selects component ClusterRoles by label. The real ruleset is the live union — what you see below is what the role actually grants right now, with each rule annotated by its source component.

1 aggregated roles, newest first by creation date.

NameCreatedComponentsComputed rulesSelectors
admin 1y 2 3 rbac.authorization.k8s.io/aggregate-to-admin=true

Role details

Expand a role to see its component ClusterRoles and computed rules.

admin 1y
2 components 3 computed rules rbac.authorization.k8s.io/aggregate-to-admin=true
Open role detail: admin
Selectors: rbac.authorization.k8s.io/aggregate-to-admin=true

Component ClusterRoles (2)

ComponentCreatedRulesMatching labels
admin-rbac 1y 1 rbac.authorization.k8s.io/aggregate-to-admin=true
admin-workloads 1y 2 rbac.authorization.k8s.io/aggregate-to-admin=true

Computed rules (3)

API groupResourcesVerbsFrom
apps deployments * admin-workloads
core pods, secrets, configmaps * admin-workloads
rbac.authorization.k8s.io roles, rolebindings get, list, watch, create, update, patch, delete admin-rbac