tool.ren

Kubernetes RBAC Permission Simulator

Analyze Roles, ClusterRoles, RoleBindings and ClusterRoleBindings locally, simulate a concrete subject request, flag privilege risks, and draft a minimal role.

All RBAC manifests and identities stay in this browser
The tool never contacts a cluster or runs kubectl; anonymous events contain only the operation, duration, and input-size bucket.

RBAC manifests and access request

Multi-document YAML and List objects, up to 5 MiB and 5,000 objects.

Subject

Access request

Load the sample or paste RBAC manifests, then simulate a concrete request.

About Kubernetes RBAC Permission Simulator

Resolve effective permissions and explain a can-i decision. Analyze Roles, ClusterRoles, RoleBindings and ClusterRoleBindings locally, simulate a concrete subject request, flag privilege risks, and draft a minimal role. The core workflow is designed to run in your current browser.

Key capabilities

  • Resolve Role and ClusterRole grants across binding scopes
  • Match verb, API group, resource, subresource, name, URL and namespace
  • Flag wildcard, Secret, exec, impersonate, bind and escalate privileges
  • Generate a reviewable least-privilege role draft for the tested request

Useful for

  • Review RBAC changes before applying them to a cluster
  • Explain why an identity can or cannot perform an operation
  • Reduce broad grants to a concrete minimal rule

Frequently asked questions

Is Kubernetes RBAC Permission Simulator free to use online?

Yes. Kubernetes RBAC Permission Simulator opens in a modern browser and does not require desktop software installation.

What is Kubernetes RBAC Permission Simulator useful for?

Common use cases include Review RBAC changes before applying them to a cluster; Explain why an identity can or cannot perform an operation.

Is my input or file uploaded?

The core processing workflow is designed to run locally in the browser. Key capabilities include Resolve Role and ClusterRole grants across binding scopes, Match verb, API group, resource, subresource, name, URL and namespace, Flag wildcard, Secret, exec, impersonate, bind and escalate privileges; account, comments, and anonymous analytics may still create normal site requests.

Comments

0 comments

Sign in to comment
AAccount

Sign in to comment and reply.

Sign in
No comments yet. Be the first to leave feedback.

ToolRen Online Toolkit © 2026