parent
5706c58fff
commit
603f810903
|
@ -32,7 +32,7 @@ some general rules that can be applied are :
|
||||||
ClusterRoleBindings to give users rights only within a specific namespace.
|
ClusterRoleBindings to give users rights only within a specific namespace.
|
||||||
- Avoid providing wildcard permissions when possible, especially to all resources.
|
- Avoid providing wildcard permissions when possible, especially to all resources.
|
||||||
As Kubernetes is an extensible system, providing wildcard access gives rights
|
As Kubernetes is an extensible system, providing wildcard access gives rights
|
||||||
not just to all object types that currently exist in the cluster, but also to all future object types
|
not just to all object types that currently exist in the cluster, but also to all object types
|
||||||
which are created in the future.
|
which are created in the future.
|
||||||
- Administrators should not use `cluster-admin` accounts except where specifically needed.
|
- Administrators should not use `cluster-admin` accounts except where specifically needed.
|
||||||
Providing a low privileged account with
|
Providing a low privileged account with
|
||||||
|
|
Loading…
Reference in New Issue