Fix kyverno exemption and mutation for automount service token
General MR
Summary
This MR accomplishes two things:
- Fixes a bug where setting serviceAccounts to be mutated and hardened as it pertains to automountServiceAccountToken settings, inadvertently exempted underlying pods from being scrutinized by this policy.
- Adds a new mutator that can be used to harden automountServiceAccountToken (set to false) on Pods; to be used in situations where upstream sets the pods to be explicitly TRUE in this regard unnecessarily.
Relates to https://repo1.dso.mil/big-bang/bigbang/-/issues/1835
Merge request reports
Activity
added statusreview label
mentioned in merge request big-bang/bigbang!3487 (merged)
removed statusreview label
added statusdoing label
assigned to @dhilgaertner2
added kyverno kyvernoPolicies labels
removed kyverno label
removed kyvernoPolicies label
removed statusdoing label
added statusreview label
requested review from @enochofori777, @snaq11092, @meganwolf, @bkhamitov, @nnewc, and @massey.robert
added kindenhancement label
added kindbug label and removed kindenhancement label
added statusdoing label and removed statusreview label
added statusreview label and removed statusdoing label
Ok this is ready for review
Edited by Dustin Hilgaertnermentioned in merge request big-bang/bigbang!3600 (merged)
mentioned in commit b4aa9228
mentioned in merge request big-bang/bigbang!3633 (merged)