Least-Privilege Role-Based Access Control Improvement for Cloud Container Security

Role-Based Access Control (RBAC) is the de-facto mechanism for preserving Kubernetes and other cloud-native container platforms, however real deployments occasionally drift away from the principle of least privilege as clusters, teams, and services improve. This paper introduces an automated RBAC ha...

Full description

Bibliographic Details
Published in:Computers
Main Authors: Waleed K. Abdulraheem, Emad Mohammed Ibbini, Hasan Kanaker, Sami Smadi, Nader Abdel Karim, Hussam N. Fakhouri, Layla Albdour, Sandi Fakhouri
Format: Article
Language:English
Published: MDPI AG 2026-05-01
Subjects:
Online Access:https://www.mdpi.com/2073-431X/15/5/326
Description
Summary:Role-Based Access Control (RBAC) is the de-facto mechanism for preserving Kubernetes and other cloud-native container platforms, however real deployments occasionally drift away from the principle of least privilege as clusters, teams, and services improve. This paper introduces an automated RBAC hardening framework that formulates least-privilege policy design as a limited optimization problem over RoleBindings and ClusterRoleBindings. The objective combines (i) a permission-risk score for namespaced and cluster-scoped actions with (ii) an operational complexity term that discourages overly large binding sets. Solid limitations encode functional requirements as well as practical security policies, which includes namespace allowlists, role scoping rules, administrative restrictions on cluster-wide bindings, binding budgets, and separation-of-duty requirements expressed by utilizing capability classes. To allow optimizer-agnostic search while protecting Kubernetes RBAC semantics, we analyze candidate policies by utilizing a unified penalty-based fitness function that compines risk, complexity, and constraint violations into a single scalar value. We utilized ten metaheuristic as a benchmark including baseline search paths on a Kubernetes-inspired instance and report feasibility and least-privilege quality metrics (precision, recall, F1, and over-privilege ratio) parallel to RB/CRB counts and excess risk as a structural indicators. Outcomes present that feasibility is the prime challenge, and is restricted to a subset of optimizers reliably arrives to entirely feasible and compact arrangements within the exact budget, indicating the practicality of metaheuristic enhancement for systematic RBAC reduction in containerized cloud computing environments.
ISSN:2073-431X