EPISODE · May 26, 2026 · 7 MIN
Why Your Kubernetes RBAC Is a Compliance Nightmare
from DevOps Daily with Fexingo: CI/CD, Kubernetes, and Modern Software Operations · host Fexingo
Episode 12 of DevOps Daily digs into Kubernetes RBAC misconfigurations — the single biggest compliance blind spot in most cloud-native environments. Lucas and Luna walk through a real incident at a mid-sized fintech where a single over-permissive ClusterRole let an attacker pivot to production data. They break down the principle of least privilege, how to audit your existing RBAC bindings with open-source tooling like kubectl-who-can and rbac-lookup, and why 'it worked in staging' is a dangerous justification for overly broad permissions. The conversation closes on whether policy-as-code tools like OPA/Gatekeeper are the right next step or just another abstraction layer. No clickbait, no fluff — just actionable DevOps ops intel. #Kubernetes #RBAC #DevOps #CloudSecurity #Compliance #LeastPrivilege #FintechIncident #kubectlWhoCan #PolicyAsCode #OPAGatekeeper #ClusterRole #ProductionSecurity #PodIdentity #Tech #DevOpsDaily #FexingoBusiness #BusinessPodcast #CloudNative Keep every episode free: buymeacoffee.com/fexingo
What this episode covers
Episode 12 of DevOps Daily digs into Kubernetes RBAC misconfigurations — the single biggest compliance blind spot in most cloud-native environments. Lucas and Luna walk through a real incident at a mid-sized fintech where a single over-permissive ClusterRole let an attacker pivot to production data. They break down the principle of least privilege, how to audit your existing RBAC bindings with open-source tooling like kubectl-who-can and rbac-lookup, and why 'it worked in staging' is a dangerous justification for overly broad permissions. The conversation closes on whether policy-as-code tools like OPA/Gatekeeper are the right next step or just another abstraction layer. No clickbait, no fluff — just actionable DevOps ops intel. #Kubernetes #RBAC #DevOps #CloudSecurity #Compliance #LeastPrivilege #FintechIncident #kubectlWhoCan #PolicyAsCode #OPAGatekeeper #ClusterRole #ProductionSecurity #PodIdentity #Tech #DevOpsDaily #FexingoBusiness #BusinessPodcast #CloudNative Keep every episode free: buymeacoffee.com/fexingo
NOW PLAYING
Why Your Kubernetes RBAC Is a Compliance Nightmare
No transcript for this episode yet
Similar Episodes
Mar 26, 2026 ·1m
Mar 19, 2026 ·34m
Feb 18, 2026 ·11m
Feb 11, 2026 ·45m