[Feature] Kyverno pods should set automountServiceAccountToken
to false
#13041
Labels
enhancement
New feature or request
good first issue
Good for newcomers
type:controller
controller related issue
Problem Statement
All Kyverno controllers use a named service account, but do not set
automountServiceAccountToken
tofalse
.This creates policy violations.
Solution Description
Set
automountServiceAccountToken
tofalse
for all controllers.Alternatives
No response
Additional Context
No response
Slack discussion
No response
Research
The text was updated successfully, but these errors were encountered: