Problem Statement
Which practice helps limit risk in a Kubernetes production cluster regarding permissions?
Explanation
Applying RBAC with least-privilege ensures each user or service account has only the permissions it needs, reducing attack surface and limiting mis-use. In production you should also combine this with network policies, pod security policies (or admission controls) and secrets management to secure your cluster.
