-
Notifications
You must be signed in to change notification settings - Fork 2.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
TODO: remove service account token from ci-kubernetes-snyk-master Prow job #33970
Comments
/label sig/security |
@tabbysable: The label(s) In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
/sig security |
@tabbysable: GuidelinesPlease ensure that the issue body includes answers to the following questions:
For more details on the requirements of such an issue, please see here and ensure that they are met. If this request no longer meets these requirements, the label can be removed In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
related: https://kubernetes.slack.com/archives/CCK68P2Q2/p1734371958722229 (it seems like probably we should move this out of the "trusted" cluster entirely?) |
/assign |
While moving the script out of inline YAML, we discussed whether a service account token was really needed by the Prow job: https://github.com/kubernetes/test-infra/pull/33817/files#r1866396666
For ease of troubleshooting, we plan to merge that PR as-is.
Once it's known working, it would be a nice least-privilege improvement to remove the service account token from that job, since we do not believe it needs one.
The text was updated successfully, but these errors were encountered: