stern --all-namespaces: namespaces is forbidden - cannot list resource "namespaces"
Routes stern -A namespace-list RBAC denials. Use when stern --all-namespaces fails with namespaces is forbidden. Not for per-namespace pods/log denials.
stern --all-namespaces fans out by listing every namespace first, and your identity can not - cluster-scoped read, so a namespaced Role can never grant it. Either get list on namespaces via a ClusterRole/ClusterRoleBinding, or scope the tail down: stern -n [ns] [query] needs only namespace-scoped rights and works today.
The error
Error from server (Forbidden): namespaces is forbidden: User "[user]" cannot list resource "namespaces" in API group "" at the cluster scopeWhat to do
- Scope down as the immediate fix:
stern -n [namespace] [query]Expected: Logs stream for that namespace.
- Or confirm the cluster-wide gap:
kubectl auth can-i list namespaces Expected: Prints no.
- Durable fix: have an admin bind a ClusterRole with list on namespaces to your user.
Expected: Prints yes; stern -A works.
When this applies
- stern --all-namespaces / -A with a namespaces forbidden error
- users with namespace-scoped roles only
- multi-tenant clusters
When it does NOT apply
- pods/log forbidden inside one namespace (different grant)
- stern failing in a single namespace (check -n and the query)
Works with
stern 1.x; RBAC-enabled clusters
stern --all-namespaces prints nothing but exits 0
Sometimes the denial surfaces as empty output. Same cause: scope to -n or get the grant.
Why it happens
-A changes stern from one namespace watch to a cluster-wide fan-out, which starts with a namespaces list call. That call is cluster-scoped, so namespace-scoped users always fail it.
Edge cases
- Some platforms forbid namespaces listing for everyone outside admins - then -A is simply unavailable and -n is the workflow.
- stern --exclude-namespace still lists namespaces first; it does not dodge the requirement.
Resolved from
gh:esysc/stern-ui (stern RBAC setup) - https://github.com/esysc/stern-ui
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.