Skip to content

Security Policy Violation: ClusterRole shouldnt use * wildcards in apiGroups, resources, or verbs #16604

@epasham

Description

@epasham

In what area(s)?

/area monitoring

Other classifications:
/kind good-first-issue

Describe the feature

knative clusterrole namespaced YAML use * wildcards in apiGroups, resources, or verbs. Wildcards violate least-privilege and grant unintended broad access

Link to the YAMLs ->
https://github.com/knative/serving/blob/main/config/core/200-roles/clusterrole-namespaced.yaml

Metadata

Metadata

Assignees

No one assigned

    Labels

    kind/featureWell-understood/specified features, ready for coding.

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions