Skip to content

ER - enable setting spec.automountServiceAccountToken to 'false' for Weblogic Server PODs controlled by WKO Operator #5345

@Michalski-Piotr

Description

@Michalski-Piotr

Hello,

One of our customer has requirement to set spec.automountServiceAccountToken to false for Weblogic Server PODs running in Kubernetes architecture (and controlled by Weblogic Operator).

This is driven by the security scan report:

**AVD-KSV-0036**
 
* AVD-KSV-0036 (MEDIUM): Container of Pod 'osb-domain-adminserver' should set 'spec.automountServiceAccountToken' to false
* AVD-KSV-0036 (MEDIUM): Container of Pod 'osb-domain-osb-server1' should set 'spec.automountServiceAccountToken' to false
* AVD-KSV-0036 (MEDIUM): Container of Pod 'osb-domain-osb-server2' should set 'spec.automountServiceAccountToken' to false

Based on analysis there is no automountServiceAccountToken field exposed as configurable based on Weblogic Kubernetes Operator domain.yaml configuration reference.

Reference: https://github.com/oracle/weblogic-kubernetes-operator/blob/release/4.2/documentation/domains/Domain.md

As Enhancement Request we would like to propose option to enable customers to configure this option for Weblogic Server pods.

Topic was discussed internally with Oracle Weblogic Kubernetes Operator Product Management Team and we have agreed to raise the Enhancement Request in GitHub.

Kind regards,
Piotr Michalski
Oracle CSS

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions