k9s Fail CRDs load: list access denied
Routes k9s CRD view RBAC failures. Use when k9s reports Fail CRDs load with list access denied on customresourcedefinitions. Not for namespaced resource denials or connection errors.
k9s lists cluster-scoped CRDs on startup and your user is not allowed to - so the CRD view fails while namespaced views may still work fine. This is an RBAC gap, not a k9s bug. Get list on customresourcedefinitions granted via a ClusterRole plus ClusterRoleBinding (it is cluster-scoped, a namespaced Role can not cover it), then restart k9s and the view loads.
The error
Fail CRDs load error="customresourcedefinitions.apiextensions.k8s.io is forbidden: User \"[user]\" cannot list resource \"customresourcedefinitions\" in API group \"apiextensions.k8s.io\" at the cluster scope"What to do
- Confirm the denial:
kubectl auth can-i list customresourcedefinitions --all-namespaces Expected: Prints no.
- Have an admin create a ClusterRole with list on customresourcedefinitions and bind it to your user.
Expected: ClusterRoleBinding created.
- Re-check:
kubectl auth can-i list customresourcedefinitions --all-namespaces Expected: Prints yes.
- Restart k9s and open the CRD view (
:crd).
Expected: CRDs load, no error banner.
When this applies
- the exact Fail CRDs load / list access denied message
- users with namespace-scoped roles only
- clusters with many CRDs where the view is actually wanted
When it does NOT apply
- forbidden on pods, deployments, etc (namespaced resources - different rule)
- k9s can not connect at all
Works with
k9s all versions; clusters with the apiextensions API
Fail get ... error="... is forbidden" on other cluster-scoped types
Same shape for nodes, namespaces, storageclasses. Same fix: ClusterRole plus ClusterRoleBinding.
Why it happens
CRDs are cluster-scoped objects, so listing them needs a cluster-scoped grant. k9s eagerly loads them for its CRD view; a user with only namespaced roles trips the check immediately.
Edge cases
- If you do not need the CRD view, you can ignore the banner - everything else keeps working.
- Some managed clusters restrict CRD listing platform-wide; then the view stays unavailable by design.
Resolved from
gh:derailed/k9s#1324 - https://github.com/derailed/k9s/issues/1324
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.