Separate ServiceAccounts and controller to follow a Least Privileges Principle
Open
kind/feature
triage/accepted
- Dominant language
- Go
- Stars
- 6.1k
- Forks
- 1.2k
- Avg merge
- 2d 7h
- Merged PRs (30d)
- 2
Description
Set serviceAccountName to individual service accounts with set of required own privileges for:
- Activator
- Autoscaler
- Controller
- Webhook
- Domainmapping-webhook
- Domainmapping-controller
See [security report](https://docs.google.com/document/d/1-6K399acPNxshUR6oZVzbPalv3L83L4F_GgRkw9js3o/edit#)
Contributor guide
Research direction
Start by reviewing the service-account configuration for Activator, Autoscaler, Controller, Webhook, Domainmapping-webhook, and Domainmapping-controller, along with the linked security report. Done means each component uses an individual service account with only its required privileges.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go, kubernetes
- Domain
- infrastructure, security
- Issue type
- Feature
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100