Skip to content

ClusterRole shouldnt use * wildcards in apiGroups, resources, or verbs #16599

@epasham

Description

@epasham

In what area(s)?

/area monitoring

Other classifications:
/kind good-first-issue

Describe the feature

knative-serving-core ClusterRole deployment YAML use * wildcards in apiGroups, resources, or verbs. Wildcards violate least-privilege and grant unintended broad access

Link to the YAML -> https://github.com/knative/serving/blob/main/config/core/200-roles/clusterrole.yaml

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/monitoringkind/featureWell-understood/specified features, ready for coding.kind/good-first-issueDenotes an issue ready for a new contributor.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions