docs(inputs.kubernetes): Document required RBAC permissions#18865
Merged
Conversation
The kubernetes input plugin uses the Kubernetes API server to discover cluster nodes when url is not set (cluster mode), which requires a ClusterRole with read access to nodes. This was not documented, leaving users unsure about what service account permissions are needed. Added a working ClusterRole and ClusterRoleBinding YAML example that documents the minimal required permissions (nodes: list, get). Also clarified that no RBAC is needed when url is explicitly set (single-node mode). Closes influxdata#16407 Signed-off-by: wucm667 <stevenwucongmin@gmail.com>
…ocs link Remove the full ClusterRole/ClusterRoleBinding YAML example to avoid maintenance burden. List the required permissions explicitly and link to the official Kubernetes RBAC documentation instead. Signed-off-by: wucm667 <stevenwucongmin@gmail.com>
srebhan
approved these changes
May 11, 2026
srebhan
pushed a commit
that referenced
this pull request
May 11, 2026
Signed-off-by: wucm667 <stevenwucongmin@gmail.com> (cherry picked from commit 471264c)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
The kubernetes input plugin uses the Kubernetes API server to discover all
cluster nodes when
urlis not set (cluster mode). This requires aClusterRolewith read access to
nodes, which was previously undocumented.Added a working
ClusterRoleandClusterRoleBindingYAML example documentingthe minimal required permissions (
nodes: list, get). Also clarified that noKubernetes RBAC is needed when
urlis explicitly set (single-node mode).Checklist
Related issues
resolves #16407