Error from server (Forbidden): pods is forbidden: User "x" cannot list resource "pods" in API group "" in the namespace
You’re authenticated to the cluster, but RBAC doesn’t give your user or service account that verb on that resource.
Seen on:
Kubernetes
Meaning
The message names the user (or system:serviceaccount:ns:name), the verb, the resource, the API group and the namespace — everything needed to write the Role/RoleBinding. In-cluster apps using the default service account hit it often.
Common causes
- No Role/ClusterRole granting the verb
- RoleBinding in a different namespace
- App running as the default service account
- Cloud IAM user not mapped to Kubernetes RBAC (EKS aws-auth / access entries)
⚡ Quick fix
- Check permission: kubectl auth can-i list pods --as=<user> -n <ns>
- Create a Role + RoleBinding for the exact verb/resource
- Set serviceAccountName on the workload
Detailed fix by platform
Kubernetes
- bash
kubectl create role pod-reader --verb=get,list,watch --resource=pods -n app kubectl create rolebinding pod-reader --role=pod-reader --serviceaccount=app:my-app -n app kubectl auth can-i list pods --as=system:serviceaccount:app:my-app -n app
How to diagnose
- Who — User/service account in the message
- What — Verb, resource, group
- Where — Namespace vs cluster scope
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Kubernetes
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026