Can this answer what a user can do?
It resolves permissions from the supplied manifests. A complete cluster answer also requires live roles, authorizer configuration, admission behavior, and other cluster context.
Resolve Kubernetes Role, ClusterRole, RoleBinding, ClusterRoleBinding, and subject relationships locally; trace permission sources and review broad access.
Paste related Role, ClusterRole, RoleBinding, and ClusterRoleBinding resources. DecodeLens resolves only the supplied manifests and shows why each subject receives a permission.
RBAC YAML or JSON
0 KB
RBAC analysis
Resolved subjects, bindings, permission rules, source relationships, and focused findings will appear here.
Support the continued development of independent, browser-local developer tools.
The analyzer links subjects to bindings, resolves supplied roles, preserves namespace scope, and shows the exact rule path behind each grant.
Continue with tools that decode, convert, inspect, or verify the same data.
Map Kubernetes contexts, clusters, users, certificates, and authentication methods; detect risky settings and export a separate redacted copy.
Open toolDecode Kubernetes Secret values, inspect nested credential and file formats, or build a masked-by-default YAML/JSON manifest locally.
Open toolInspect AWS IAM identity, resource, and role trust policies; expand statements and conditions, and highlight broad or high-impact permissions locally.
Open toolConvert JSON and YAML in either direction, validate syntax, and inspect the result as a tree.
Open toolPaste the related roles and bindings together, inspect critical/high findings, then select a subject to trace each grant back to its binding and role.
Role + RoleBinding + subjectssubject → binding → role → permission rulesIt resolves permissions from the supplied manifests. A complete cluster answer also requires live roles, authorizer configuration, admission behavior, and other cluster context.
No. It parses the pasted or selected files locally and performs no cluster, DNS, or network request.
aggregationRule selects other ClusterRoles by labels. Without the complete selected role set, the final rule list cannot be reconstructed truthfully.
No. Parsing and relationship analysis run in a disposable browser worker and manifest content is not included in analytics.