Open
Description
User Story
As a security operator, I want to ensure developers who have access to create MachineDeployments are not able to gain access to data for workloads on a cluster they are not supposed to.
Detailed Description
kubeadm bootstrap tokens allow registration as arbitrary node names. GCP, EKS and Kops provide mechanisms to attest to the identity of a node such that they do not inadvertently get access to secrets and volumes not intended for that node. Provide a mechanism to resolve.
Anything else you would like to add:
[Miscellaneous information that will assist in solving the issue.]
/kind feature
Metadata
Metadata
Assignees
Labels
Issues or PRs related to securityDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.Categorizes issue or PR as related to a new feature.Important over the long term, but may not be staffed and/or may need multiple releases to complete.Categorizes an issue or PR as relevant to SIG Security.Indicates an issue or PR is ready to be actively worked on.