Everything is an API object.

Untitled

Authentication

RBAC since 1.6

Only allow rules, no deny rules (like security group)

Untitled

Kubernetes doesn’t manage users at all. You have to manage users externally

Service accounts are used and managed by clusters

Untitled

Authorization

Untitled

Change Kubernetes config file.