kubernetes-sigs / kubernetes-sigs/node-readiness-controller

Update threat model to explain the elevation of privileges thru CRDs

Open
#178 2 comments 0 reactions 1 assignee Claimed by @ajaysundark View on GitHub
Dominant language
Go
Stars
163
Forks
74
Avg merge
2d 18h
Merged PRs (30d)
9

Description

The https://github.com/kubernetes-sigs/node-readiness-controller/blob/main/docs/book/src/operations/security.md is covering the Node Condition reporting and explain permissions required by the "agent".

However, there is another backdoor escalation of privileges thru the creation of CRDs. If permissions needed to create configuration (NodeReadinessRule) to remove certain taint is lower than permissions needed to remove the taint from the Node, it needs to be articulated.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.