Skip to content

Disable a deployment from being able to update it's service account using noupdateserviceaccount #95

@nissessenap

Description

@nissessenap

If someone get's in to a deployment with access to to update other deployments they shouldn't be able to update there own deployment and point to another service account. This is a simple way of escalating your access in a cluster.

https://github.com/open-policy-agent/gatekeeper-library/tree/master/library/general/noupdateserviceaccount

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions