8000 [Feature] Kyverno pods should set `automountServiceAccountToken` to false · Issue #13041 · kyverno/kyverno · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

[Feature] Kyverno pods should set automountServiceAccountToken to false #13041

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
2 tasks done
JimBugwadia opened this issue May 7, 2025 · 1 comment
Open
2 tasks done
Assignees
Labels
enhancement New feature or request good first issue Good for newcomers type:controller controller related issue

Comments

@JimBugwadia
Copy link
Member

Problem Statement

All Kyverno controllers use a named service account, but do not set automountServiceAccountToken to false.

This creates policy violations.

Solution Description

Set automountServiceAccountToken to false for all controllers.

Alternatives

No response

Additional Context

No response

Slack discussion

No response

Research

  • I have read and followed the documentation AND the troubleshooting guide.
  • I have searched other issues in this repository and mine is not recorded.
@JimBugwadia JimBugwadia added enhancement New feature or request triage Default label assigned to all new issues indicating label curation is needed to fully organize. good first issue Good for newcomers and removed triage Default label assigned to all new issues indicating label curation is needed to fully organize. labels May 7, 2025
@dosubot dosubot bot added the type:controller controller related issue label May 7, 2025
@Denish3436
Copy link
Contributor

/assign

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request good first issue Good for newcomers type:controller controller related issue
Projects
None yet
Development

No branches or pull requests

2 participants
0