Forbidden ☸️ Kubernetes

Error from server (Forbidden): pods is forbidden: User "x" cannot list resource "pods" in API group "" in the namespace

You’re authenticated to the cluster, but RBAC doesn’t give your user or service account that verb on that resource.

Seen on: Kubernetes

Meaning

The message names the user (or system:serviceaccount:ns:name), the verb, the resource, the API group and the namespace — everything needed to write the Role/RoleBinding. In-cluster apps using the default service account hit it often.

Common causes

  • No Role/ClusterRole granting the verb
  • RoleBinding in a different namespace
  • App running as the default service account
  • Cloud IAM user not mapped to Kubernetes RBAC (EKS aws-auth / access entries)

⚡ Quick fix

  1. Check permission: kubectl auth can-i list pods --as=<user> -n <ns>
  2. Create a Role + RoleBinding for the exact verb/resource
  3. Set serviceAccountName on the workload

Detailed fix by platform

Kubernetes

  1. bash
    kubectl create role pod-reader --verb=get,list,watch --resource=pods -n app
    kubectl create rolebinding pod-reader --role=pod-reader --serviceaccount=app:my-app -n app
    kubectl auth can-i list pods --as=system:serviceaccount:app:my-app -n app

How to diagnose

  1. Who — User/service account in the message
  2. What — Verb, resource, group
  3. Where — Namespace vs cluster scope

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.