-
Couldn't load subscription status.
- Fork 141
Move automountServiceAccountToken to Pod #3573
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Problem: For security reasons, it's best practice to not have `automountServiceToken` on the ServiceAccount, and instead set in directly on the workloads that need the token. Solution: Set this field on the Pods instead of the ServiceAccounts.
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## main #3573 +/- ##
=======================================
Coverage 86.85% 86.85%
=======================================
Files 127 127
Lines 15218 15220 +2
Branches 62 62
=======================================
+ Hits 13218 13220 +2
Misses 1848 1848
Partials 152 152 ☔ View full report in Codecov by Sentry. 🚀 New features to boost your workflow:
|
|
@sjberman Will this pr wait on a reply from the original poster to your question about configurability? |
|
@bjee19 I don't think it needs to. |
Move automountServiceToken to Pod Problem: For security reasons, it's best practice to not have `automountServiceToken` on the ServiceAccount, and instead set in directly on the workloads that need the token. Solution: Set this field on the Pods instead of the ServiceAccounts.
Move automountServiceToken to Pod Problem: For security reasons, it's best practice to not have `automountServiceToken` on the ServiceAccount, and instead set in directly on the workloads that need the token. Solution: Set this field on the Pods instead of the ServiceAccounts.
Problem: For security reasons, it's best practice to not have
automountServiceTokenon the ServiceAccount, and instead set in directly on the workloads that need the token.Solution: Set this field on the Pods instead of the ServiceAccounts.
Closes #3540
Checklist
Before creating a PR, run through this checklist and mark each as complete.
Release notes
If this PR introduces a change that affects users and needs to be mentioned in the release notes,
please add a brief note that summarizes the change.