stern --all-namespaces fans out by listing every namespace first, and your identity can not - cluster-scoped read, so a namespaced Role can never grant it. Either get list on namespaces via a ClusterRole/ClusterRoleBinding, or scope the tail down: stern -n [ns] [query] needs only namespace-scoped rights and works today.

## The error
```text
Error from server (Forbidden): namespaces is forbidden: User "[user]" cannot list resource "namespaces" in API group "" at the cluster scope
```

## What to do
1. Scope down as the immediate fix:
```bash
stern -n [namespace] [query]
```
   Expected: Logs stream for that namespace.
2. Or confirm the cluster-wide gap:
```bash
kubectl auth can-i list namespaces
```
   Expected: Prints `no`.
3. Durable fix: have an admin bind a ClusterRole with list on namespaces to your user.
   Expected: Prints `yes`; stern -A works.

## When this applies
- stern --all-namespaces / -A with a namespaces forbidden error
- users with namespace-scoped roles only
- multi-tenant clusters

## When it does NOT apply
- pods/log forbidden inside one namespace (different grant)
- stern failing in a single namespace (check -n and the query)

## Works with
stern 1.x; RBAC-enabled clusters

### stern --all-namespaces prints nothing but exits 0
Sometimes the denial surfaces as empty output. Same cause: scope to -n or get the grant.

## Why it happens
-A changes stern from one namespace watch to a cluster-wide fan-out, which starts with a namespaces list call. That call is cluster-scoped, so namespace-scoped users always fail it.

## Edge cases
- Some platforms forbid namespaces listing for everyone outside admins - then -A is simply unavailable and -n is the workflow.
- stern --exclude-namespace still lists namespaces first; it does not dodge the requirement.

## Resolved from
gh:esysc/stern-ui (stern RBAC setup) - https://github.com/esysc/stern-ui