-
Notifications
You must be signed in to change notification settings - Fork 308
Open
Labels
lifecycle/staleDenotes an issue or PR has remained open with no activity and has become stale.Denotes an issue or PR has remained open with no activity and has become stale.
Description
CAPV controllers currently appear to have Kubernetes RBAC permissions defined that are not strictly necessary for the controller's actual operational logic. These unused permissions introduce security concerns.
To adhere to the principle of least privilege, we should audit our existing cluster roles and bindings and trim them down to only the resources and verbs that are actively consumed by the controller processes.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
lifecycle/staleDenotes an issue or PR has remained open with no activity and has become stale.Denotes an issue or PR has remained open with no activity and has become stale.