The use of utility programs that can be capable of overriding system and application controls shall be restricted and tightly controlled.
KubeAid enforces strict control over privileged operations by integrating Keycloak for secure access, combined with Kubernetes RBAC and role-based access profiles. This ensures that only authenticated and authorized personnel can perform elevated actions within the cluster, supported by full session auditing and command-level visibility.
Cluster and server access is based on the principle of least privilege, with separate roles for operators, administrators, and automation systems. Privileged utilities are available only to specific roles and isolated namespaces or hosts.