Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-6716

[dns-operator] - Minimize wildcard/privilege Usage in Cluster and Local Roles

XMLWordPrintable

    • Moderate
    • None
    • 1
    • Sprint 248
    • 1
    • Rejected
    • False
    • Hide

      None

      Show
      None
    • 10/14 Support case is 2 1/2+ years old and was opened against 4.8. Likely this bug represents a legitimate problem but is low priority.

      According http://static.open-scap.org/ssg-guides/ssg-ocp4-guide-cis.html#xccdf_org.ssgproject.content_rule_rbac_wildcard_use the usage of wildcard in ClusterRole and Roles should be prevented as best as possible.
      
      Further, one should refrain from using cluster-admin permissions to comply with CIS security requirements.
      
      It's therefore requested to review the below serviceAccount and their associated Roles as they were found not to be compliant with the above and restrict permissions further to the extend possible.
      
       - system:serviceaccount:openshift-dns-operator:dns-operator
      

              alebedev@redhat.com Andrey Lebedev
              rhn-support-sreber Simon Reber
              Hongan Li Hongan Li
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

                Created:
                Updated:
                Resolved: