[Verse 1]
When you need to check what someone else can do
In your cluster there's a way to see it through
Use kubectl auth can-i with their name in line
Add dash dash as equals and their username fine
[Chorus]
Can they create pods, can they delete files
Check another user's permissions for a while
Auth can-i tells you yes or no today
What they're allowed to do and what's kept away
[Verse 2]
Create pods question mark, add dash dash as user
Type their name right there, now you're not a loser
The command will answer if they have the right
To make new pods or if it's out of sight
[Chorus]
Can they create pods, can they delete files
Check another user's permissions for a while
Auth can-i tells you yes or no today
What they're allowed to do and what's kept away
[Bridge]
Want to check if someone's got the master key
Use star star for everything they might see
Cluster admin powers, do they have them all
Auth can-i star star tells you if they'll fall
[Verse 3]
Single quotes around each star will make it right
Check for cluster admin with this powerful sight
If they get a yes back then they rule the land
Every resource, every verb is in their hand
[Chorus]
Can they create pods, can they delete files
Check another user's permissions for a while
Auth can-i tells you yes or no today
What they're allowed to do and what's kept away
[Outro]
Before you grant access, check what they can do
Auth can-i keeps your cluster safe and true