You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
KIM should only be allowed to read the secrets which are relevant for it to work. Extensive access to secrets it not required and has to be limited to the minimum.
Allowed secrets are:
secrets containing KIM configuration parameters
kubeconfig-secrets of SKRs
AC:
KIM can access only secrets required by it to work (see list above)
Expected result
KIM is not allowed to read any secrets which are not required by KIM to run/operate.
Actual result
Secret permissions are not fully limited on KCP and KIm could read more as required.
Steps to reproduce
Troubleshooting
The text was updated successfully, but these errors were encountered:
tobiscr
changed the title
HASI: Limit permissions to read only relevant secrets by KIM
HASI: Limit permissions to read only relevant secrets by KIM [DEADLINE: EOY]
Oct 2, 2024
Description
KIM should only be allowed to read the secrets which are relevant for it to work. Extensive access to secrets it not required and has to be limited to the minimum.
Allowed secrets are:
AC:
Expected result
KIM is not allowed to read any secrets which are not required by KIM to run/operate.
Actual result
Secret permissions are not fully limited on KCP and KIm could read more as required.
Steps to reproduce
Troubleshooting
The text was updated successfully, but these errors were encountered: