{"id":"rbac-subject-apigroup-defaults","text":"ServiceAccount subjects use `\"\"` (empty) apiGroup and require a namespace field; User and Group subjects use `rbac.authorization.k8s.io` apiGroup and must not specify a namespace.","truth_value":"IN","source":"entries/2026/03/05/en-documentation-openshift_container_platform-417-html-rbac_apis-rolebinding-rba.md","source_url":"","source_hash":"8ab3126e09c6eed3","justifications":[],"dependents":[],"metadata":{},"explanation":{"steps":[{"node":"rbac-subject-apigroup-defaults","truth_value":"IN","reason":"premise"}]}}