Uploaded image for project: 'OpenShift Service Mesh'
  1. OpenShift Service Mesh
  2. OSSM-1231

Minimize privileges in operator's ClusterRole

    XMLWordPrintable

Details

    • 5
    • False
    • None
    • False
    • Sprint 61, Sprint 62

    Description

      According http://static.open-scap.org/ssg-guides/ssg-ocp4-guide-cis.html#xccdf_org.ssgproject.content_rule_rbac_wildcard_use the usage of wildcard in ClusterRole and Roles should be prevented as best as possible.

      Further, one should refrain from using `cluster-admin` permissions to comply with CIS security requirements.

      It's therefore requested to review the below serviceAccount and their associated Roles as they were found not to be compliant with the above and restrict permissions further to the extend possible.

      • system:serviceaccount:openshift-operators:istio-operator

       

      Acceptance criteria:

      • make sure that we don't grant unnecessary permissions

      Attachments

        Activity

          People

            Unassigned Unassigned
            rhn-support-sreber Simon Reber
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated: