You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The idea that anything should be granted * on secrets in all namespaces? Concerning. At the very least, we need to really understand why this is needed. We need to go back through, once Rook and Ceph are implemented, so that we can make sure that all of the permissions we're granting are reasonable.
Might also want to do this for things that aren't Rook/Ceph.
The text was updated successfully, but these errors were encountered:
As I'm working on #29, it's becoming apparent that there are some mildly questionable security choices in Rook's configuration, like the following:
The idea that anything should be granted
*
onsecrets
in all namespaces? Concerning. At the very least, we need to really understand why this is needed. We need to go back through, once Rook and Ceph are implemented, so that we can make sure that all of the permissions we're granting are reasonable.Might also want to do this for things that aren't Rook/Ceph.
The text was updated successfully, but these errors were encountered: