12 Public Cloud k8s Cluster Master Node 参考) https://kubernetes.io/docs/reference/access-authn-authz/ https://medium.com/better-programming/k8s-tips-using-a-serviceaccount-801c433d0023 API Version • Extension • Core • Apps *** Resources • Deployment • Node • Pod *** Action • Create • Get • List *** Human Namespace縛り Pod用 User用 Admission Control 認証 認可 k8s cluster Guard rail • ResourceQuota • LimitRange • AlwaysPullImages • NamespaceLifecycle • Priority • Pod Security Policy *** IAM OpenID Connect IAM Role for Service Account IAM aws-auth