UNCLASSIFIED - NO CUI

Skip to content
Snippets Groups Projects
Commit 34a4f2b1 authored by Michael Martin's avatar Michael Martin
Browse files

Merge branch...

Merge branch 'fix-automount-serviceaccount-token-for-stateful-and-deps-monitoring-loki' into 'master'

closing loophole in monitoring/loki  - statefulsets and deployments - automountserviceaccounttoken

See merge request !3867
parents 9e44ee74 ca44a50f
No related branches found
No related tags found
1 merge request!3867closing loophole in monitoring/loki - statefulsets and deployments - automountserviceaccounttoken
Pipeline #2905587 passed
......@@ -751,8 +751,6 @@ policies:
# Enforcing said policies requires access to the API to get/list resources
- twistlock-defender-ds-*
- namespace: logging
serviceAccounts:
- logging-loki-*
pods:
allow:
- logging-loki-minio-ss-*
......@@ -846,13 +844,12 @@ policies:
- namespace: monitoring
pods:
allow:
- monitoring-grafana-*
- monitoring-grafana-*
- monitoring-grafana*
- monitoring-monitoring-kube-admission-create-*
- monitoring-monitoring-kube-admission-patch-*
- monitoring-monitoring-kube-state-metrics-*
- monitoring-monitoring-kube-operator-*
- prometheus-monitoring-monitoring-kube-prometheus-*
- monitoring-monitoring-kube-state-metrics*
- monitoring-monitoring-kube-operator*
- prometheus-monitoring-monitoring-kube-prometheus*
- namespace: anchore
pods:
allow:
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment