Is there a way to see RBAC events for GKE clusters?

Viewed 87

I have a GKE cluster that uses a mix of Cloud IAM and cluster RBAC rules for resource access. For granularity, we use RBAC bindings for certain resources on the cluster, but I'm unable to find a place where those events are logged.

How do I see the logs for when cluster RBAC denies a user the permissions to do something? I can only see IAM related logs in Cloud Logging's audit logs. I'd like to know when the cluster itself denies access.

2 Answers

You can find the GCP events in the GKE audit logs as described here.

The RBAC related events can be obtained from the kubeapi server as described here

Related