# RBAC question regarding role inheritance

**URL:** <https://forums.suse.com/t/rbac-question-regarding-role-inheritance/14691>\
**Category:** SUSE Rancher Prime\
**Created:** [July 1, 2019, 9:20pm UTC](https://forums.suse.com/t/rbac-question-regarding-role-inheritance/14691 "2019-07-01T21:20:13Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mgoya](https://avatars.discourse-cdn.com/v4/letter/m/f0a364/32.png) [@mgoya](https://forums.suse.com/u/mgoya)\
**Post date:** [July 1, 2019, 9:20pm UTC](https://forums.suse.com/t/rbac-question-regarding-role-inheritance/14691/1 "2019-07-01T21:20:13Z")

</div>

Hello,  
I am trying to understand what permissions the “Kubernetes admin” and “Kubernetes edit” roles have defined for them. I see they are defined for both “project-owner” and “project-member”. I am working on creating some custom Rancher project roles and would like to know the permissions defined for these Kubernetes roles. I haven’t had any luck Googling around. Thanks

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [July 2, 2019, 5:57am UTC](https://forums.suse.com/t/rbac-question-regarding-role-inheritance/14691/2 "2019-07-02T05:57:49Z")

</div>

You can get the clusterrole from kubectl if you want to see the specific rules, but there’s a tl;dr here: [https://kubernetes.io/blog/2017/10/using-rbac-generally-available-18/#granting-access-to-users](https://kubernetes.io/blog/2017/10/using-rbac-generally-available-18/#granting-access-to-users) .
