Unused ClusterRole knative-serving-istio #995
Labels
kind/enhancement
lifecycle/frozen
Indicates that an issue or PR should not be auto-closed due to staleness.
triage/accepted
Issues which should be fixed (post-triage)
ClusterRole
knative-serving-istio
seems to not be binding to any RoleBinding/ClusterRoleBindings.https://github.com/knative-sandbox/net-istio/blob/main/config/200-clusterrole.yaml
net-istio-controller
Deployment is using the ServiceAccountcontroller
which is used by the knative-serving Controller. This ServiceAccount already has the following permissions from ClusterRoleknative-serving-admin
It would be ideal for net-istio-controller to use its own ServiceAccount with its own permissions and follow the principle of least privilege
The text was updated successfully, but these errors were encountered: