問題文
A developer needs read access to Pods in one namespace only. Which pair of RBAC objects grants exactly that?
選択肢
- A Role in that namespace listing the read verbs on pods, plus a RoleBinding in the same namespace that names the developer.
- A Role in that namespace, plus a ClusterRoleBinding that names the developer, so the grant reaches every namespace.
- A ClusterRole listing the read verbs on pods, plus a ClusterRoleBinding that names the developer, and the cluster-scoped binding is what makes the permission take effect.
- A ClusterRole carrying a deny rule for the other namespaces, so only the intended one is left open.