-
Bug
-
Resolution: Unresolved
-
Normal
-
None
-
4.8.0
-
None
-
Incidents & Support
-
False
-
-
False
-
-
-
(This bug was reported by a customer via sluetzen )
Current documentation (4.8) says:
Match if the deployment’s Kubernetes service account has Kubernetes RBAC permission level equal to = or greater than > the specified level.
And lists the options as one of:
DEFAULT
ELEVATED_IN_NAMESPACE
ELEVATED_CLUSTER_WIDE
CLUSTER_ADMIN
While these field names provide a hint of what they are supposed to represent, the description lacks the actual explanation of those fields. For example is that a direct mapping to Kubernetes values, or it that synthesized by ACS to represent a more holistic evaluation, and if so, what the logic is.
- is cloned by
-
ROX-31096 Policy Docs: wrong and missing explanation of "ADD Command used instead of COPY" policy
-
- To Do
-