# Kubectl auth can-i --list for service accounts

**URL:** <https://discuss.kubernetes.io/t/kubectl-auth-can-i-list-for-service-accounts/9644>\
**Category:** General Discussions\
**Created:** [February 8, 2020, 8:44pm UTC](https://discuss.kubernetes.io/t/kubectl-auth-can-i-list-for-service-accounts/9644 "2020-02-08T20:44:07Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![sbail](https://avatars.discourse-cdn.com/v4/letter/s/8baadc/32.png) [@sbail](https://discuss.kubernetes.io/u/sbail)\
**Post date:** [February 8, 2020, 8:44pm UTC](https://discuss.kubernetes.io/t/kubectl-auth-can-i-list-for-service-accounts/9644/1 "2020-02-08T20:44:07Z")

</div>

I have a service account called steve running in the default namespace with a **role binding** to **cluster role** allowing read access to nodes and /metrics.

How should I interpret the output for kubectl auth can-i --list when it is applied for different namespaces ? More specifically nodes and /metrics are not namespaced, why are they not showing in all outputs?

Case 1) I see nodes and /metrics when listing actions the service account can perform in the default namespace

 ![image](https://us1.discourse-cdn.com/flex016/uploads/kubernetes/original/2X/7/75d3907f636038e5a0d11733228236888516c716.png)

Case 2) I don’t see nodes and /metrics when listing actions the service account can perform in the kube-system namespace

master $ kubectl auth can-i --list --as=system:serviceaccount:default:steve --namespace=kube-system  
Resources Non-Resource URLs Resource Names Verbs  
_._ [_]  
[_] [_]  
 [selfsubjectaccessreviews.authorization.k8s.io](http://selfsubjectaccessreviews.authorization.k8s.io) [] [] [create]  
 [selfsubjectrulesreviews.authorization.k8s.io](http://selfsubjectrulesreviews.authorization.k8s.io) [] [] [create]  
[/api/_] [get]  
[/api] [get]  
[/apis/_] [] [get]  
[/apis] [] [get]  
[/healthz] [] [get]  
[/healthz] [] [get]  
[/openapi/_] [get]  
[/openapi] [get]  
[/version/] [get]  
[/version/] [get]  
[/version] [get]  
[/version] [get]

Thank you!
