Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Non-default ServiceAccounts #195

Closed
brancz opened this issue Mar 4, 2021 · 1 comment
Closed

Non-default ServiceAccounts #195

brancz opened this issue Mar 4, 2021 · 1 comment

Comments

@brancz
Copy link
Member

brancz commented Mar 4, 2021

All components use the default service account right now which is problematic from a security standpoint, as in GCP for example through workload identity the object storage bucket permissions are given through the service account, so even components that don't need object storage access get it currently.

I'll prepare a PR to create a ServiceAccount per component.

@kakkoyun @metalmatze

@brancz
Copy link
Member Author

brancz commented Mar 4, 2021

Closed by #196

@brancz brancz closed this as completed Mar 4, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant