Every request to the API server is authenticated as a user or a ServiceAccount and then authorized. On kind 14,561 , as on kubeadm 5,150 and the managed services, the authorizer that matters is RBAC (role-based access control): nothing is allowed until a role grants it, and roles only add permissions, never subtract them.