Skip to content

Limit the scope of registration secrets and allow rejection ClusterRegistrationTokens with no TTL #5157

@0xavi0

Description

@0xavi0

As an enhancement, Fleet could limit the access to registration secrets to only the cluster that's going to read it.
The name is generated randomly and a different downstream cluster would need to apply brute force to guess the secret name, but as an enhancement it would be to good to fine grain the access rights.

Also, another enhancement related to cluster registration would be to reject ClusterRegistrationTokens with TTL set to 0 or nil.

Metadata

Metadata

Assignees

No fields configured for Feature.

Projects

Status

🆕 New

Relationships

None yet

Development

No branches or pull requests

Issue actions