knative / knative/serving

Separate ServiceAccounts and controller to follow a Least Privileges Principle

Open
#13,857 1 comment 0 reactions 0 assignees View on GitHub
kind/feature triage/accepted
Dominant language
Go
Stars
6.1k
Forks
1.2k
Avg merge
2d 7h
Merged PRs (30d)
2

Description

Set serviceAccountName to individual service accounts with set of required own privileges for:

- Activator
- Autoscaler
- Controller
- Webhook
- Domainmapping-webhook
- Domainmapping-controller

See [security report](https://docs.google.com/document/d/1-6K399acPNxshUR6oZVzbPalv3L83L4F_GgRkw9js3o/edit#)

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the service-account configuration for Activator, Autoscaler, Controller, Webhook, Domainmapping-webhook, and Domainmapping-controller, along with the linked security report. Done means each component uses an individual service account with only its required privileges.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, kubernetes
Domain
infrastructure, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.