{"adoption": {"forks": 83, "observed_at": "2026-08-28T04:03:37.770270+00:00", "stars": 1112}, "canonical_url": "https://ross.abutalabs.com/products/audit2rbac", "card": {"archived": false, "artifact_type": "cli-tool", "description": "Autogenerate RBAC policies based on Kubernetes audit logs", "domain": ["security", "developer-tools"], "enriched": true, "function": ["authorization", "security", "cli", "developer-tools"], "health_score": 20, "homepage": null, "language": "Go", "license": "NOASSERTION", "license_family": "other", "maturity": "maintenance", "member_repos": ["liggitt/audit2rbac"], "name": "liggitt/audit2rbac", "platform": ["cli", "windows", "cross-platform"], "pushed_at": "2023-02-11T07:11:26+00:00", "repo": "liggitt/audit2rbac", "stars": 1112, "tags": ["kubernetes", "rbac", "audit-logs", "openshift", "policy-generation", "go", "devops", "linux", "macos"], "topics": ["kubernetes", "rbac", "authorization", "openshift", "audit"], "urls": [], "use_cases": ["generate kubernetes rbac roles from audit logs", "create least-privilege role bindings for a service account", "figure out what permissions a user actually needs", "autogenerate rbac yaml instead of guessing permissions", "audit what api calls an app makes and scope its access", "convert broad cluster-admin access into minimal rbac rules"], "what_it_is": "audit2rbac is a Go CLI tool that takes a Kubernetes audit log and a username as input and generates RBAC Role and RoleBinding objects covering all API requests made by that user. It automates least-privilege RBAC policy authoring from observed API activity.", "when_to_avoid": ["you need RBAC policy management or continuous enforcement rather than one-time generation", "you don't have audit logging enabled or can't capture the full set of API requests", "you need authorization mechanisms other than Kubernetes RBAC"], "when_to_choose": ["you have kubernetes audit logs in JSON format and want to derive exact RBAC policies for a user or service account", "you want to replace overly broad permissions with least-privilege roles based on observed behavior", "you run Kubernetes or OpenShift and need to author Role/RoleBinding manifests quickly"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/audit2rbac", "repo": "liggitt/audit2rbac", "role": "main", "score": 23}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:03:37.770270+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T06:42:48.345002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c95eba3d81406c08a03cee1acf1b3e45e220f8187de6dcb36ed25876e19e6b74", "fetched_at": "2026-08-28T04:03:37.770270+00:00", "kind": "readme", "missing": false, "url": "https://github.com/liggitt/audit2rbac"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:03:37.770270+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T06:42:48.345002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c95eba3d81406c08a03cee1acf1b3e45e220f8187de6dcb36ed25876e19e6b74", "fetched_at": "2026-08-28T04:03:37.770270+00:00", "kind": "readme", "missing": false, "url": "https://github.com/liggitt/audit2rbac"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T06:42:48.345002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c95eba3d81406c08a03cee1acf1b3e45e220f8187de6dcb36ed25876e19e6b74", "fetched_at": "2026-08-28T04:03:37.770270+00:00", "kind": "readme", "missing": false, "url": "https://github.com/liggitt/audit2rbac"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:03:37.770270+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:03:37.770270+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:03:37.770270+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T06:42:48.345002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c95eba3d81406c08a03cee1acf1b3e45e220f8187de6dcb36ed25876e19e6b74", "fetched_at": "2026-08-28T04:03:37.770270+00:00", "kind": "readme", "missing": false, "url": "https://github.com/liggitt/audit2rbac"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:03:37.770270+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:03:37.770270+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T06:42:48.345002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c95eba3d81406c08a03cee1acf1b3e45e220f8187de6dcb36ed25876e19e6b74", "fetched_at": "2026-08-28T04:03:37.770270+00:00", "kind": "readme", "missing": false, "url": "https://github.com/liggitt/audit2rbac"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:03:37.770270+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:03:37.770270+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:03:37.770270+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T06:42:48.345002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c95eba3d81406c08a03cee1acf1b3e45e220f8187de6dcb36ed25876e19e6b74", "fetched_at": "2026-08-28T04:03:37.770270+00:00", "kind": "readme", "missing": false, "url": "https://github.com/liggitt/audit2rbac"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:03:37.770270+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:03:37.770270+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T06:42:48.345002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c95eba3d81406c08a03cee1acf1b3e45e220f8187de6dcb36ed25876e19e6b74", "fetched_at": "2026-08-28T04:03:37.770270+00:00", "kind": "readme", "missing": false, "url": "https://github.com/liggitt/audit2rbac"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T06:42:48.345002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c95eba3d81406c08a03cee1acf1b3e45e220f8187de6dcb36ed25876e19e6b74", "fetched_at": "2026-08-28T04:03:37.770270+00:00", "kind": "readme", "missing": false, "url": "https://github.com/liggitt/audit2rbac"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T06:42:48.345002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c95eba3d81406c08a03cee1acf1b3e45e220f8187de6dcb36ed25876e19e6b74", "fetched_at": "2026-08-28T04:03:37.770270+00:00", "kind": "readme", "missing": false, "url": "https://github.com/liggitt/audit2rbac"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T06:42:48.345002+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "c95eba3d81406c08a03cee1acf1b3e45e220f8187de6dcb36ed25876e19e6b74", "fetched_at": "2026-08-28T04:03:37.770270+00:00", "kind": "readme", "missing": false, "url": "https://github.com/liggitt/audit2rbac"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 0, "longevity": 100, "rhythm": 8}, "computed_at": "2026-09-02T17:46:02.011165+00:00", "flags": ["no_license"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 3279, "days_push": 1299, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 23, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}