# Will AutoDiscovery work with a Role and RoleBinding in kubernetes

**URL:** <https://discuss.elastic.co/t/will-autodiscovery-work-with-a-role-and-rolebinding-in-kubernetes/248584>\
**Category:** Beats\
**Tags:** docker, filebeat\
**Created:** [September 14, 2020, 9:48pm UTC](https://discuss.elastic.co/t/will-autodiscovery-work-with-a-role-and-rolebinding-in-kubernetes/248584 "2020-09-14T21:48:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![TejaV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tejav/32/71553_2.png) [@TejaV](https://discuss.elastic.co/u/TejaV)\
**Post date:** [September 14, 2020, 9:48pm UTC](https://discuss.elastic.co/t/will-autodiscovery-work-with-a-role-and-rolebinding-in-kubernetes/248584/1 "2020-09-14T21:48:27Z")

</div>

Hi,

I like the autodiscovery feature of filebeat (as a Daemonset) but I was reluctant to use a clusterRole and clusterRoleBinding as part of my kubernetes deployment. Apparently I'm not allowed to use a clusterRoleBinding as I am not the owner of the kubernetes cluster. **I can only fetch logs in my kubernetes namespace.**

1. Is it possible for FileBeat's autoDiscovery feature to work with Role and RoleBinding?
2. If not, do we have any other secured way-forward from Elastic?

Thanks,  
Teja

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [September 15, 2020, 7:07am UTC](https://discuss.elastic.co/t/will-autodiscovery-work-with-a-role-and-rolebinding-in-kubernetes/248584/2 "2020-09-15T07:07:29Z")

</div>

Please take a look at this thread [Limiting Filebeat Autodiscover to Namespace](https://discuss.elastic.co/t/limiting-filebeat-autodiscover-to-namespace/234803) . You may find answers to your questions.

---

<div class="post-metadata">

**Author:** ![TejaV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tejav/32/71553_2.png) [@TejaV](https://discuss.elastic.co/u/TejaV)\
**Post date:** [September 17, 2020, 11:28am UTC](https://discuss.elastic.co/t/will-autodiscovery-work-with-a-role-and-rolebinding-in-kubernetes/248584/3 "2020-09-17T11:28:12Z")

</div>

Thanks Role and RoleBinding helped me to fetch logs from the current namespace 🙂

Just to double-check, Having a Role (for the current namespace) or a clusterRole (for all or set of namespaces) do the same work in terms of updating k8s metadata? Is there any difference? Will I miss any important feature or flexibility if I use a Role? Does filebeat still need extra security privileges while using a role instead of clusterRole?

In another way, having clusterRole will help me to fetch logs from all or a specific set of namespaces, and having a role helps me to get the current namespace. Did I understand it correctly?

As I mentioned earlier, I don't want to use a clusterRole and also not interested in all namespaces.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 15, 2020, 1:28pm UTC](https://discuss.elastic.co/t/will-autodiscovery-work-with-a-role-and-rolebinding-in-kubernetes/248584/4 "2020-10-15T13:28:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
