問題文
An auditor asks why access to etcd must be restricted even though the cluster has a carefully designed set of RBAC rules. Which explanation is correct?
選択肢
- The rules themselves are stored in etcd as objects, so a client with direct access could read them and work out which service account holds the permissions that it needs.
- RBAC is evaluated by the API server, so a client that talks to etcd directly reads and writes cluster state without any of those rules being consulted.
- The rules simply have no effect there because etcd maintains its own separate set of Roles and RoleBindings, so a direct client is still constrained by whatever those say.
- The rules apply there only to write operations, so a direct read of the stored objects needs no permission at all.