UNCLASSIFIED - NO CUI

Skip to content
Snippets Groups Projects

Resolve "Mitigate automountServiceAccountToken findings in promtail"

Merged Sam Vongsay requested to merge 1831-mitigate-automountSAT-promtail into master
@@ -693,6 +693,7 @@ policies:
- anchore
- fortify
- vault
- promtail
update-automountserviceaccounttokens:
enabled: true
@@ -841,7 +842,12 @@ policies:
- vault-vault
- vault-vault-root-token-secret
- vault-vault-agent-injector
- namespace: promtail
serviceAccounts:
- promtail-promtail
pods:
- promtail-promtail-*
istio:
enabled: {{ .Values.istio.enabled }}
Loading