All features Requires Kubius Pro

RBAC explorer

Make sense of cluster access control without reading YAML. Kubius resolves effective permissions from your Roles, ClusterRoles and their bindings, answering both directions of the question.

  • “What can this subject do?” - every rule a ServiceAccount, user or group holds, grouped by scope
  • “Who can delete pods in prod?” - reverse-lookup any verb / resource / namespace
  • High-privilege rules flagged automatically (wildcards, secrets, escalate / bind / impersonate)
  • Shows the exact binding → role path behind every grant

Unlock rbac explorer with Kubius Pro

14-day free trial, no credit card. macOS Sonoma (14) or later.

Start free trial