Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Restrict service account impersonation #179

Closed
stefanprodan opened this issue Nov 20, 2020 · 1 comment · Fixed by #180
Closed

Restrict service account impersonation #179

stefanprodan opened this issue Nov 20, 2020 · 1 comment · Fixed by #180
Assignees
Labels
area/kustomize Kustomize related issues and pull requests

Comments

@stefanprodan
Copy link
Member

Do not allow a Kustomization to reference a service account from a different namespace to prevent privilege escalation.

Ref: fluxcd/flux2#263

@stefanprodan stefanprodan added the area/kustomize Kustomize related issues and pull requests label Nov 20, 2020
@stefanprodan stefanprodan self-assigned this Nov 20, 2020
@danieliziourov-form3
Copy link

But what if I want that feature? :D

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/kustomize Kustomize related issues and pull requests
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants