Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

Kubernetes RBAC API

Role-based access control resources including Roles, RoleBindings, ClusterRoles, and ClusterRoleBindings for managing authorization.

Kubernetes RBAC API is one of 7 APIs that Kubernetes publishes on the APIs.io network, described by a machine-readable OpenAPI specification and an AsyncAPI event-driven specification.

This API exposes 1 JSON Schema definition.

Tagged areas include RBAC. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, authentication docs, an AsyncAPI specification, and 1 JSON Schema.

This API exposes 2 operations across 1 path, and defines 7 schemas. It is described by OpenAPI 3.1.0, at version v1.32.0.

Requests are made against a single base URL, https://kubernetes.default.svc.

2 operations 1 paths 7 schemas 1 GET1 POST

Metadata

The identity and technical contract details declared by the specification.

Specification
OpenAPI 3.1.0
API Version
v1.32.0
Base URL
https://kubernetes.default.svc
Authentication
HTTP Bearer, Mutual TLS
Terms of Service
Resource Areas
1

Authentication & Security 2

Kubernetes RBAC API declares 2 security schemes for authenticating requests. It accepts HTTP bearer tokens (JWT) (bearerAuth). It requires mutual TLS (clientCertificate). By default, every request must be authenticated.

  • bearerAuth — Kubernetes service account token or user token issued by the cluster's authentication provider. Include in the Authorization header as 'Bearer '.
  • clientCertificate — Client certificate authentication using a TLS certificate issued by the cluster's certificate authority.

Paths & Operations 2

Across 1 path, the API surfaces 2 operations — 1 GET, 1 POST. Each is listed below with its method, path, parameters, and response codes.

RBAC 2

Role-based access control resources including Roles, RoleBindings, ClusterRoles, and ClusterRoleBindings for managing authorization.

GET
/apis/rbac.authorization.k8s.io/v1/clusterroles
Kubernetes List ClusterRoles
listClusterRoles 3 params → 200401
POST
/apis/rbac.authorization.k8s.io/v1/clusterroles
Kubernetes Create a ClusterRole
createClusterRole body → 201400401

Schemas 7

The contract defines 7 schemas that model the data the API accepts and returns. The most detailed are ObjectMeta (10 properties), Status (6 properties), OwnerReference (5 properties), ClusterRole (4 properties). Each schema is shown below with its type and property counts.

ObjectMeta
object
Standard Kubernetes object metadata included on all persistent resources. Contains identifying information, ownership references, and system-managed fields lik…
10 properties
OwnerReference
object
Reference to an owning resource that manages this object's lifecycle via garbage collection.
5 properties 4 required
PolicyRule
object
A rule that grants a set of verbs on a set of resources within an API group. All fields are combined with AND logic.
4 properties
Status
object
Status is a return value for calls that don't return other objects. It is used to convey error messages, reasons, and codes for both success and failure respon…
6 properties
ListMeta
object
Metadata that all list responses include, containing pagination state and the resource version of the list.
3 properties
ClusterRoleList
object
A list of ClusterRoles returned by list operations.
4 properties 1 required
ClusterRole
object
A ClusterRole defines a set of permissions applicable across the entire cluster. Rules grant access to specific API groups, resources, and verbs. ClusterRoles…
4 properties

Specification

The full machine-readable OpenAPI contract behind this narrative.

Source

kubernetes-rbac-api-openapi.yml Raw ↑

Other APIs Kubernetes publishes across the network.

Kubernetes Autoscaling API
Kubernetes Cluster API
Kubernetes Config API
Kubernetes Events API
Kubernetes Namespaces API
Kubernetes Workloads API