# io.k8s.api.authorization.v1.SubjectRulesReviewStatus

From **Kubernetes**.

SubjectRulesReviewStatus contains the result of a rules check. This check can be incomplete depending on the set of authorizers the server is configured with and any errors experienced during evaluation. Because authorization rules are additive, if a rule appears in a list it's safe to assume the subject has that permission, even if that list is incomplete.

- Type: `object`

## Properties

### `evaluationError`

- Required: false
- Type: `string`

evaluationError can appear in combination with Rules. It indicates an error occurred during rule evaluation, such as an authorizer that doesn't support rule evaluation, and that ResourceRules and/or NonResourceRules may be incomplete.

### `incomplete`

- Required: true
- Type: `boolean`
- Default: `false`

incomplete is true when the rules returned by this call are incomplete. This is most commonly encountered when an authorizer, such as an external authorizer, doesn't support rules evaluation.

### `nonResourceRules`

- Required: true
- Type: `array`

nonResourceRules is the list of actions the subject is allowed to perform on non-resources. The list ordering isn't significant, may contain duplicates, and possibly be incomplete.

### `resourceRules`

- Required: true
- Type: `array`

resourceRules is the list of actions the subject is allowed to perform on resources. The list ordering isn't significant, may contain duplicates, and possibly be incomplete.

## JSON Schema

```json
{"description":"SubjectRulesReviewStatus contains the result of a rules check. This check can be incomplete depending on the set of authorizers the server is configured with and any errors experienced during evaluation. Because authorization rules are additive, if a rule appears in a list it's safe to assume the subject has that permission, even if that list is incomplete.","properties":{"evaluationError":{"description":"evaluationError can appear in combination with Rules. It indicates an error occurred during rule evaluation, such as an authorizer that doesn't support rule evaluation, and that ResourceRules and/or NonResourceRules may be incomplete.","type":"string"},"incomplete":{"default":false,"description":"incomplete is true when the rules returned by this call are incomplete. This is most commonly encountered when an authorizer, such as an external authorizer, doesn't support rules evaluation.","type":"boolean"},"nonResourceRules":{"description":"nonResourceRules is the list of actions the subject is allowed to perform on non-resources. The list ordering isn't significant, may contain duplicates, and possibly be incomplete.","items":{"$ref":"#/components/schemas/io.k8s.api.authorization.v1.NonResourceRule"},"type":"array","x-kubernetes-list-type":"atomic"},"resourceRules":{"description":"resourceRules is the list of actions the subject is allowed to perform on resources. The list ordering isn't significant, may contain duplicates, and possibly be incomplete.","items":{"$ref":"#/components/schemas/io.k8s.api.authorization.v1.ResourceRule"},"type":"array","x-kubernetes-list-type":"atomic"}},"required":["resourceRules","nonResourceRules","incomplete"],"type":"object"}
```
