VectleSkillsk9s Fail CRDs load: list access denied

k9s Fail CRDs load: list access denied

Export

Routes k9s CRD view RBAC failures. Use when k9s reports Fail CRDs load with list access denied on customresourcedefinitions. Not for namespaced resource denials or connection errors.

k9s lists cluster-scoped CRDs on startup and your user is not allowed to - so the CRD view fails while namespaced views may still work fine. This is an RBAC gap, not a k9s bug. Get list on customresourcedefinitions granted via a ClusterRole plus ClusterRoleBinding (it is cluster-scoped, a namespaced Role can not cover it), then restart k9s and the view loads.

The error

Fail CRDs load error="customresourcedefinitions.apiextensions.k8s.io is forbidden: User \"[user]\" cannot list resource \"customresourcedefinitions\" in API group \"apiextensions.k8s.io\" at the cluster scope"

What to do

  1. Confirm the denial:
kubectl auth can-i list customresourcedefinitions --all-namespaces

Expected: Prints no.

  1. Have an admin create a ClusterRole with list on customresourcedefinitions and bind it to your user.

Expected: ClusterRoleBinding created.

  1. Re-check:
kubectl auth can-i list customresourcedefinitions --all-namespaces

Expected: Prints yes.

  1. Restart k9s and open the CRD view (:crd).

Expected: CRDs load, no error banner.

When this applies

  • the exact Fail CRDs load / list access denied message
  • users with namespace-scoped roles only
  • clusters with many CRDs where the view is actually wanted

When it does NOT apply

  • forbidden on pods, deployments, etc (namespaced resources - different rule)
  • k9s can not connect at all

Works with

k9s all versions; clusters with the apiextensions API

Fail get ... error="... is forbidden" on other cluster-scoped types

Same shape for nodes, namespaces, storageclasses. Same fix: ClusterRole plus ClusterRoleBinding.

Why it happens

CRDs are cluster-scoped objects, so listing them needs a cluster-scoped grant. k9s eagerly loads them for its CRD view; a user with only namespaced roles trips the check immediately.

Edge cases

  • If you do not need the CRD view, you can ignore the banner - everything else keeps working.
  • Some managed clusters restrict CRD listing platform-wide; then the view stays unavailable by design.

Resolved from

gh:derailed/k9s#1324 - https://github.com/derailed/k9s/issues/1324

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=k9s+Fail+CRDs+load%3A+list+access+denied&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.