<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cluster-Administration on IT Comparison</title><link>https://comparison.metacog.co.kr/tags/cluster-administration/</link><description>Recent content in Cluster-Administration on IT Comparison</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 02 Aug 2026 11:24:24 +0900</lastBuildDate><atom:link href="https://comparison.metacog.co.kr/tags/cluster-administration/index.xml" rel="self" type="application/rss+xml"/><item><title>Role vs ClusterRole: Kubernetes RBAC Scope Compared</title><link>https://comparison.metacog.co.kr/posts/2026-08-02-role-vs-clusterrole-kubernetes-rbac-scope-compared/</link><pubDate>Sun, 02 Aug 2026 11:24:24 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-02-role-vs-clusterrole-kubernetes-rbac-scope-compared/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Role and ClusterRole are both Kubernetes RBAC objects that define sets of permission rules (verbs on resources), but they differ in scope: a Role only applies within a single namespace, while a ClusterRole is defined once for the whole cluster and can be bound either cluster-wide or scoped down to one namespace. Understanding this distinction is essential for applying least-privilege access control in multi-tenant clusters.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;defs&gt;&lt;marker id="arrowA" viewBox="0 0 10 10" refX="5" refY="5" markerWidth="6" markerHeight="6" orient="auto-start-reverse"&gt;&lt;path d="M0,0L10,5L0,10z" style="fill:var(--compare-a)"/&gt;&lt;/marker&gt;&lt;marker id="arrowB" viewBox="0 0 10 10" refX="5" refY="5" markerWidth="6" markerHeight="6" orient="auto-start-reverse"&gt;&lt;path d="M0,0L10,5L0,10z" style="fill:var(--compare-b)"/&gt;&lt;/marker&gt;&lt;/defs&gt;&lt;text x="155" y="35" text-anchor="middle" font-size="20" font-weight="bold" style="fill:var(--primary)"&gt;Role&lt;/text&gt;&lt;text x="477" y="35" text-anchor="middle" font-size="20" font-weight="bold" style="fill:var(--primary)"&gt;ClusterRole&lt;/text&gt;&lt;rect x="30" y="55" width="250" height="270" rx="6" style="fill:none;stroke:var(--border)" stroke-width="1.5" stroke-dasharray="5 5"/&gt;&lt;text x="45" y="75" font-size="12" style="fill:var(--secondary)"&gt;Namespace: dev&lt;/text&gt;&lt;rect x="90" y="95" width="130" height="44" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="155" y="122" text-anchor="middle" font-size="14" style="fill:var(--content)"&gt;Role&lt;/text&gt;&lt;line x1="155" y1="139" x2="155" y2="174" style="stroke:var(--compare-a)" stroke-width="2" marker-end="url(#arrowA)"/&gt;&lt;rect x="90" y="177" width="130" height="40" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="155" y="202" text-anchor="middle" font-size="13" style="fill:var(--content)"&gt;RoleBinding&lt;/text&gt;&lt;line x1="155" y1="217" x2="155" y2="254" style="stroke:var(--compare-a)" stroke-width="2" marker-end="url(#arrowA)"/&gt;&lt;circle cx="155" cy="278" r="20" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="155" y="282" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;User&lt;/text&gt;&lt;text x="155" y="316" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;limited to this namespace&lt;/text&gt;&lt;rect x="345" y="55" width="265" height="270" rx="6" style="fill:none;stroke:var(--border)" stroke-width="1.5"/&gt;&lt;text x="360" y="75" font-size="12" style="fill:var(--secondary)"&gt;Cluster scope&lt;/text&gt;&lt;rect x="412" y="95" width="140" height="44" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="482" y="122" text-anchor="middle" font-size="14" style="fill:var(--content)"&gt;ClusterRole&lt;/text&gt;&lt;line x1="450" y1="139" x2="417" y2="174" style="stroke:var(--compare-b)" stroke-width="2" marker-end="url(#arrowB)"/&gt;&lt;line x1="514" y1="139" x2="558" y2="174" style="stroke:var(--compare-b)" stroke-width="2" marker-end="url(#arrowB)"/&gt;&lt;rect x="360" y="177" width="110" height="36" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="415" y="199" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;RoleBinding&lt;/text&gt;&lt;rect x="495" y="177" width="130" height="36" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="560" y="199" text-anchor="middle" font-size="10" style="fill:var(--content)"&gt;ClusterRoleBinding&lt;/text&gt;&lt;line x1="415" y1="213" x2="415" y2="248" style="stroke:var(--compare-b)" stroke-width="2" marker-end="url(#arrowB)"/&gt;&lt;line x1="560" y1="213" x2="560" y2="248" style="stroke:var(--compare-b)" stroke-width="2" marker-end="url(#arrowB)"/&gt;&lt;circle cx="415" cy="268" r="18" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="415" y="272" text-anchor="middle" font-size="10" style="fill:var(--content)"&gt;User&lt;/text&gt;&lt;text x="415" y="300" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;this ns only&lt;/text&gt;&lt;circle cx="560" cy="268" r="18" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="560" y="272" text-anchor="middle" font-size="10" style="fill:var(--content)"&gt;User&lt;/text&gt;&lt;text x="560" y="300" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;all namespaces&lt;/text&gt;&lt;text x="477" y="318" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;one definition, reused via either binding&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Role&lt;/th&gt;
&lt;th&gt;ClusterRole&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;API object scope&lt;/td&gt;
&lt;td&gt;Namespaced object; exists only within one Namespace&lt;/td&gt;
&lt;td&gt;Cluster-scoped object; exists once for the entire cluster&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Resources it can grant access to&lt;/td&gt;
&lt;td&gt;Only namespaced resources (pods, configmaps, secrets, etc.) within its own namespace&lt;/td&gt;
&lt;td&gt;Namespaced resources cluster-wide plus cluster-scoped resources such as nodes, persistentvolumes, and namespaces&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Non-resource URLs (e.g. /healthz, /metrics)&lt;/td&gt;
&lt;td&gt;Cannot reference non-resource URLs&lt;/td&gt;
&lt;td&gt;Can include rules for non-resource URLs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Binding object required&lt;/td&gt;
&lt;td&gt;RoleBinding only, created in the same namespace&lt;/td&gt;
&lt;td&gt;RoleBinding for a namespace-scoped grant, or ClusterRoleBinding for a cluster-wide grant&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Effective grant when bound&lt;/td&gt;
&lt;td&gt;Permissions always limited to the Role&amp;rsquo;s own namespace&lt;/td&gt;
&lt;td&gt;Spans every namespace when bound via ClusterRoleBinding, or just one namespace when bound via RoleBinding&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Reuse across namespaces&lt;/td&gt;
&lt;td&gt;Must be duplicated in each namespace that needs the same rules&lt;/td&gt;
&lt;td&gt;Defined once, reused across many namespaces or cluster-wide via separate bindings&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Aggregation support&lt;/td&gt;
&lt;td&gt;None; rules are static within the object&lt;/td&gt;
&lt;td&gt;Supports aggregationRule to auto-combine rules from other ClusterRoles by label selector&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Typical built-in examples&lt;/td&gt;
&lt;td&gt;None shipped by default; teams author their own per namespace&lt;/td&gt;
&lt;td&gt;cluster-admin, admin, edit, view, and system: component roles ship as default ClusterRoles&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong class="kw"&gt;Role&lt;/strong&gt; is namespace-scoped while &lt;strong class="kw"&gt;ClusterRole&lt;/strong&gt; is cluster-scoped by definition, regardless of how it&amp;rsquo;s later bound.&lt;/li&gt;
&lt;li&gt;Only ClusterRole can grant access to cluster-scoped resources like nodes or to &lt;strong class="kw"&gt;non-resource URLs&lt;/strong&gt; such as /metrics.&lt;/li&gt;
&lt;li&gt;A ClusterRole can still be restricted to one namespace by binding it with a &lt;strong class="kw"&gt;RoleBinding&lt;/strong&gt; instead of a ClusterRoleBinding.&lt;/li&gt;
&lt;li&gt;ClusterRole supports &lt;strong class="kw"&gt;aggregation&lt;/strong&gt; to compose permissions from labeled ClusterRoles; Role has no equivalent mechanism.&lt;/li&gt;
&lt;li&gt;Kubernetes ships default admin/edit/view permission sets as &lt;strong class="kw"&gt;built-in ClusterRoles&lt;/strong&gt;, never as Roles.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Role&lt;/strong&gt;&lt;/p&gt;</description></item></channel></rss>