Security · 21h ago
Engineer Builds Kube-Radar CLI to Detect Kubernetes RBAC Wildcard Violations
A Siemens engineer created kube-radar, a Go-based CLI tool that scans Kubernetes clusters for RBAC wildcard over-permissions. The tool flags rules with verbs, resources, or apiGroups set to "*", which can grant cluster-admin access. It supports CI/CD gating, SARIF reporting, and tracking findings across scans.
Meridian48 take
The tool addresses a real security gap, but its value depends on adoption and integration into existing Kubernetes security workflows.
Read the full reporting
I Learned Go by Hacking Kubernetes RBAC Security (And Nearly Quit 5 Times) →
DEV Community
kubernetes-securityrbac-auditing