VectleSkillskubens: namespaces is forbidden - cannot list resource "namespaces"

kubens: namespaces is forbidden - cannot list resource "namespaces"

Export

Routes kubens RBAC list denials. Use when kubens fails because listing namespaces is forbidden (often followed by no namespace exists with name). Not for plain typos.

kubens lists all namespaces to validate your choice, and your identity is not allowed to - common on Rancher and locked-down clusters. The misleading no namespace exists line is just kubens failing closed after the denied list. Work around it with kubens --force [name] (sets the namespace without verifying, per the atago spec), or get list on namespaces granted.

The error

Error from server (Forbidden): namespaces is forbidden: User "[user]" cannot list resource "namespaces" in API group "" at the cluster scope
error: no namespace exists with name "[name]".

What to do

  1. Confirm the RBAC gap:
kubectl auth can-i list namespaces

Expected: Prints no.

  1. Set the namespace without the list check:
kubens --force [name]

Expected: Namespace set in the context without contacting the list API.

  1. Verify it took:
kubectl config view --minify -o jsonpath='{.contexts[0].context.namespace}'

Expected: Prints the namespace name.

  1. Durable fix: have an admin grant list on namespaces, or at least get on the specific namespace.

Expected: kubens works without --force.

When this applies

  • kubens failing with a Forbidden line on namespaces
  • Rancher and other RBAC-heavy platforms
  • single-namespace users who can not list

When it does NOT apply

  • plain typos where you CAN list namespaces (drop --force, fix the name)
  • forbidden on pods or other resources

Works with

kubens (ahmetb/kubectx) with --force

interactive kubens picker shows nothing

Same denied list behind the picker. Use kubens --force [name] with the exact name.

Why it happens

kubens validates names by listing namespaces, a cluster-scoped read. Users scoped to one namespace usually lack it, so the validation - not the namespace - is what fails.

Edge cases

  • --force skips validation entirely, so a typo lands you in a nonexistent namespace - double-check the name.
  • kubectl config set-context --current --namespace=[name] never validates either, which is the same escape hatch.

Resolved from

gh:ahmetb/kubectx#83 - https://github.com/ahmetb/kubectx/issues/83

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=kubens%3A+namespaces+is+forbidden+-+cannot+list+resource+%22namespaces%22&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.